First published: Fri Oct 13 2017(Updated: )
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ranger | =0.4.0 | |
Apache Ranger | =0.5.0 | |
Apache Ranger | =0.5.1 | |
Apache Ranger | =0.5.2 | |
Apache Ranger | =0.5.3 | |
Apache Ranger | =0.6.0 | |
Apache Ranger | =0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-6815 is categorized as medium due to the potential unauthorized privilege escalation.
To fix CVE-2016-6815, upgrade Apache Ranger to version 0.6.2 or later where this issue has been resolved.
Users with the 'keyadmin' role in Apache Ranger versions prior to 0.6.2 are affected by CVE-2016-6815.
The impact of CVE-2016-6815 allows users with a 'keyadmin' role to change passwords for 'admin' role users, potentially compromising the system's security.
CVE-2016-6815 was reported in 2016, highlighting a vulnerability in Apache Ranger prior to version 0.6.2.