CVE-2022-45048: Apache Ranger: code execution vulnerability in policy expressions
Published May 4, 2023
·Updated
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
Affected Software
1 affected component
Apache Ranger=2.3.0
Event History
May 5, 2023
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Data Sourced
08:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-45048?
CVE-2022-45048 is considered a critical vulnerability due to its potential for unauthorized code execution.
2
How do I fix CVE-2022-45048?
To mitigate CVE-2022-45048, users should upgrade Apache Ranger to version 2.4.0 or later.
3
Who is affected by CVE-2022-45048?
CVE-2022-45048 affects users of Apache Ranger version 2.3.0 who have appropriate privileges to create policies.
4
What kind of vulnerability is CVE-2022-45048?
CVE-2022-45048 is a code execution vulnerability that can be exploited through policy expressions.
5
Is there a workaround for CVE-2022-45048?
There are no known workarounds for CVE-2022-45048; the only solution is to upgrade to an unaffected version.