Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2022-26850 Vulnerability in maven package org.apache.nifi:nifi-single-user-utils
CVE-2021-41183 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2022-36909 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2022-23945 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2009-2625 Vulnerability in maven package xerces:xercesimpl