CVE-2024-55532: Apache Ranger: Improper Neutralization of Formula Elements in a CSV File
Published Mar 3, 2025
·Updated
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.
Affected Software
3 affected componentsFixes available
Apache Ranger<2.6.0
maven/org.apache.ranger:security-admin-web<2.6.0
2.6.0
Apache Ranger<2.6.0
Event History
Mar 3, 2025
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-55532?
CVE-2024-55532 has a severity rating that indicates it poses a risk due to improper neutralization of formula elements.
2
How do I fix CVE-2024-55532?
To fix CVE-2024-55532, users should upgrade Apache Ranger to version 2.6.0 or later.
3
Which version of Apache Ranger is affected by CVE-2024-55532?
CVE-2024-55532 affects Apache Ranger versions prior to 2.6.0.
4
What components of Apache Ranger are impacted by CVE-2024-55532?
CVE-2024-55532 specifically impacts the Export CSV feature of Apache Ranger.
5
Who is affected by CVE-2024-55532?
Any user utilizing versions of Apache Ranger below 2.6.0 that use the Export CSV feature is affected by CVE-2024-55532.