Description
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Remediation
References
http://www.securityfocus.com/bid/98958
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
Related Vulnerabilities
CVE-2017-16194 Vulnerability in npm package picard
CVE-2019-15597 Vulnerability in npm package node-df
CVE-2022-1440 Vulnerability in npm package git-interface
CVE-2022-45210 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bcprov-jdk18on