Fiche vulnérabilité
CVE-2022-45048 : faille élevée Apache Software Foundation Apache Ranger (CVSS 8.4)
Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
En bref
- Sévérité
- Élevée (CVSS 8.4)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 5 mai 2023
- Dernière mise à jour
- 15 oct. 2024
Produits concernés
- Apache Software Foundation Apache Ranger