CVE-2015-0266

HIGH7.1EPSS 0.11%

Apache Ranger allows users to bypass intended access restrictions via direct access to module URLs

Published: 5/17/2022Modified: 4/14/2025

Description

The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.1CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

References (7)