CVE-2016-0735: High severity apache ranger vulnerability
Published Apr 11, 2016
·Updated
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.
Affected Software
3 affected componentsFixes available
Apache Ranger=0.5.0
Apache Ranger=0.5.1
maven/org.apache.ranger:ranger>=0.5.0<0.5.2
0.5.2
Event History
Apr 11, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-0735?
CVE-2016-0735 is classified as a medium severity vulnerability due to its potential impact on resource-level access restrictions.
2
How do I fix CVE-2016-0735?
To fix CVE-2016-0735, upgrade Apache Ranger to version 0.5.2 or later.
3
Who is affected by CVE-2016-0735?
CVE-2016-0735 affects Apache Ranger versions 0.5.0 and 0.5.1.
4
What is the nature of CVE-2016-0735?
CVE-2016-0735 allows remote authenticated users to bypass parent resource-level access restrictions through mishandling of policies.
5
What versions of Apache Ranger should be updated due to CVE-2016-0735?
Versions 0.5.0 and 0.5.1 of Apache Ranger should be updated to 0.5.2 or later to mitigate CVE-2016-0735.