Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2022-47937 Vulnerability in maven package org.apache.sling:org.apache.sling.commons.json
CVE-2021-31811 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2022-38750 Vulnerability in maven package org.yaml:snakeyaml
CVE-2022-23974 Vulnerability in maven package org.apache.pinot:pinot-server
CVE-2019-16775 Vulnerability in maven package org.webjars.npm:bin-links