Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Remediation
References
https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6
Related Vulnerabilities
CVE-2021-42357 Vulnerability in maven package org.apache.knox:gateway-service-knoxsso
CVE-2020-13925 Vulnerability in maven package org.apache.kylin:kylin-server
CVE-2019-0187 Vulnerability in maven package org.apache.jmeter:apachejmeter_core
CVE-2018-11804 Vulnerability in maven package org.apache.spark:spark-core_2.10
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-api