CVE-2024-55532
Apache Ranger Improper Neutralization of Formula Elements vulnerability
EPSS 0.54%
Description
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.
How to fix CVE-2024-55532
To remediate CVE-2024-55532, upgrade the affected package to a fixed version below.
- Maven/org.apache.ranger:security-admin-web—upgrade to 2.6.0 or later
Is CVE-2024-55532 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.6.0