Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-server-webapp
CVE-2021-37695 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2020-1945 Vulnerability in maven package org.apache.ant:ant
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2018-11764 Vulnerability in maven package org.apache.hadoop:hadoop-core