CVE-2024-45479
CRITICALApache Ranger 2.4.0 - Server-Side Request Forgery in Edit Service Page
Title source: llmDescription
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/01/21/4
Vendor Advisory vendor-advisory
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Scores
CVSS v3
9.1
EPSS
0.0029
EPSS Percentile
52.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-918
Status
published
Products (2)
apache/ranger
2.4.0 - 2.5.0
org.apache.ranger/ranger
0 - 2.5.0Maven
Published
Jan 21, 2025
Tracked Since
Feb 18, 2026