Description
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
Remediation
References
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
http://www.securityfocus.com/bid/95998
Related Vulnerabilities
CVE-2023-45818 Vulnerability in npm package tinymce
CVE-2023-43494 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2019-20343 Vulnerability in maven package org.codehaus.mojo:exec-maven-plugin
CVE-2023-37478 Vulnerability in npm package @pnpm/linux-arm64