Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2020-2292 Vulnerability in maven package org.jenkins-ci.plugins:release
CVE-2019-10281 Vulnerability in maven package org.jenkins-ci.plugins:relution-publisher
CVE-2019-10445 Vulnerability in maven package org.jenkins-ci.plugins:google-kubernetes-engine
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http3:http3-qpack