CVE-2016-8746

MEDIUM

Apache Ranger <0.6.3 - Info Disclosure

Title source: llm

Description

Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.

Scores

CVSS v3 5.9
EPSS 0.0054
EPSS Percentile 67.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-426
Status published
Products (3)
apache/ranger < 0.6.2
org.apache.ranger/ranger-plugins-common < 0.6.3Maven
Apache Software Foundation/Apache Ranger < 0.6.0 - 0.6.2
Published Jun 14, 2017
Tracked Since Feb 18, 2026