Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2023-31582 Vulnerability in maven package org.bitbucket.b_c:jose4j
CVE-2021-41249 Vulnerability in npm package graphql-playground-react
CVE-2018-3258 Vulnerability in maven package mysql:mysql-connector-java
CVE-2019-19771 Vulnerability in npm package babel-loqder
CVE-2020-11021 Vulnerability in npm package @actions/http-client