Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2023-30530 Vulnerability in maven package org.jenkins-ci.plugins:consul-kv-builder
CVE-2020-14060 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-28169 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2018-11765 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2021-21193 Vulnerability in maven package org.webjars.npm:electron