Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2021-36774 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2020-13929 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2020-28450 Vulnerability in npm package decal
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2021-33609 Vulnerability in maven package com.vaadin:vaadin-server