First published: Mon Apr 11 2016(Updated: )
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | <=0.4.0. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0266 is considered a medium severity vulnerability due to its potential impact on access control.
To fix CVE-2015-0266, upgrade Apache Ranger to version 0.5.0 or later.
CVE-2015-0266 affects all versions of Apache Ranger prior to 0.5.0 that have been deployed.
CVE-2015-0266 allows remote authenticated users to bypass intended access restrictions specifically to module URLs.
No formal workaround is documented for CVE-2015-0266 other than upgrading to a fixed version.