CVE-2016-8746
MEDIUMApache Ranger <0.6.3 - Info Disclosure
Title source: llmDescription
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
Scores
CVSS v3
5.9
EPSS
0.0054
EPSS Percentile
67.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-426
Status
published
Products (3)
apache/ranger
< 0.6.2
org.apache.ranger/ranger-plugins-common
< 0.6.3Maven
Apache Software Foundation/Apache Ranger
< 0.6.0 - 0.6.2
Published
Jun 14, 2017
Tracked Since
Feb 18, 2026