CVE-2015-0266: High severity apache ranger vulnerability
Published Apr 11, 2016
·Updated
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.
Affected Software
2 affected componentsFixes available
Apache Ranger<=0.4.0.
maven/org.apache.ranger:ranger<0.5.0
0.5.0
Event History
Apr 11, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-0266?
CVE-2015-0266 is considered a medium severity vulnerability due to its potential impact on access control.
2
How do I fix CVE-2015-0266?
To fix CVE-2015-0266, upgrade Apache Ranger to version 0.5.0 or later.
3
Who is affected by CVE-2015-0266?
CVE-2015-0266 affects all versions of Apache Ranger prior to 0.5.0 that have been deployed.
4
What types of access can be bypassed due to CVE-2015-0266?
CVE-2015-0266 allows remote authenticated users to bypass intended access restrictions specifically to module URLs.
5
Is there a workaround for CVE-2015-0266?
No formal workaround is documented for CVE-2015-0266 other than upgrading to a fixed version.