CVE-2015-5167: Medium severity apache ranger vulnerability
Published Apr 12, 2016
·Updated
The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.
Affected Software
2 affected componentsFixes available
Apache Ranger<=0.5.0
maven/org.apache.ranger:ranger<0.5.1
0.5.1
Event History
Apr 12, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-5167?
CVE-2015-5167 has a medium severity rating due to its potential for access control bypass.
2
How do I fix CVE-2015-5167?
To fix CVE-2015-5167, upgrade Apache Ranger to version 0.5.1 or later.
3
Who is affected by CVE-2015-5167?
Remote authenticated users who have access to the REST API in Apache Ranger versions prior to 0.5.1 are affected by CVE-2015-5167.
4
What type of vulnerability is CVE-2015-5167?
CVE-2015-5167 is an access control vulnerability that allows unauthorized access through the REST API.
5
What versions of Apache Ranger are impacted by CVE-2015-5167?
Apache Ranger versions prior to 0.5.1 are impacted by CVE-2015-5167.