Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2018-6342 Vulnerability in maven package org.webjars.npm:react-dev-utils
CVE-2018-11093 Vulnerability in npm package @ckeditor/ckeditor5-link
CVE-2018-1047 Vulnerability in maven package org.wildfly:wildfly-undertow
CVE-2023-43497 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2264 Vulnerability in maven package org.jenkins-ci.plugins:custom-job-icon