CVE-2015-5167

MEDIUM6.5EPSS 0.16%

Apache Ranger allows users to bypass intended access restrictions via the REST API

Published: 5/17/2022Modified: 4/14/2025

Description

The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References (6)