Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2023-32732 Vulnerability in maven package io.grpc:grpc-protobuf
CVE-2022-42466 Vulnerability in maven package org.apache.isis.viewer:isis-viewer-wicket-ui
CVE-2019-10474 Vulnerability in maven package org.jenkins-ci.plugins:global-post-script
CVE-2021-21290 Vulnerability in maven package io.netty:netty-codec-http
CVE-2020-2113 Vulnerability in maven package org.jenkins-ci.tools:git-parameter