CVE-2016-8746

MEDIUM

Apache Ranger <0.6.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95998

Scores

CVSS v3 5.9
EPSS 0.0054
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-426
Status published
Products (3)
apache/ranger < 0.6.2
Apache Software Foundation/Apache Ranger 0.6.0 - 0.6.2
org.apache.ranger/ranger-plugins-common 0 - 0.6.3Maven
Published Jun 14, 2017
Tracked Since Feb 18, 2026