Vulnerability Description
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ranger | <= 0.6.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95998Third Party AdvisoryVDB Entry
- https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+RangRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/95998Third Party AdvisoryVDB Entry
- https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+RangRelease NotesVendor Advisory
FAQ
What is CVE-2016-8746?
CVE-2016-8746 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
How severe is CVE-2016-8746?
CVE-2016-8746 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8746?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ranger.