Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2020-5251 Vulnerability in npm package parse-server
CVE-2020-29455 Vulnerability in npm package liveaddress
CVE-2022-25644 Vulnerability in npm package @pendo324/get-process-by-name
CVE-2016-3092 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-10380 Vulnerability in maven package org.jenkins-ci.plugins:simple-travis-runner