Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2020-7709 Vulnerability in npm package json-pointer
CVE-2020-35214 Vulnerability in maven package io.atomix:atomix
CVE-2017-0928 Vulnerability in npm package html-janitor
CVE-2020-2293 Vulnerability in maven package org.jenkins-ci.plugins:persona
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors