CVE-2016-8746: Medium severity apache ranger vulnerability
Published Jun 14, 2017
·Updated
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.
Affected Software
2 affected componentsFixes available
Apache Ranger<=0.6.2
maven/org.apache.ranger:ranger-plugins-common<0.6.3
0.6.3
Event History
Jun 14, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Oct 17, 2018
Advisory Published
05:22 PM
Frequently Asked Questions
1
What is the severity of CVE-2016-8746?
CVE-2016-8746 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2016-8746?
To mitigate CVE-2016-8746, update Apache Ranger to version 0.6.3 or later.
3
What systems are affected by CVE-2016-8746?
CVE-2016-8746 affects Apache Ranger versions prior to 0.6.3.
4
What type of vulnerability is CVE-2016-8746?
CVE-2016-8746 is categorized as a flaw in the policy engine that improperly matches paths.
5
What conditions trigger the CVE-2016-8746 vulnerability?
The vulnerability occurs when policies are configured without wildcards and the recursion flag is set to true.