Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-standalone
CVE-2018-25031 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2020-10992 Vulnerability in maven package com.linkedin.azkaban:azkaban-common
CVE-2019-10184 Vulnerability in maven package io.undertow:undertow-servlet
CVE-2018-1000820 Vulnerability in maven package org.neo4j.procedure:apoc