https://seclists.org/oss-sec/2023/q2/124: CVE-2022-45048: Apache Ranger: code execution vulnerability in policy expressions
Published May 4, 2023
·Updated
Affected Software
1 affected component
Apache Ranger
Frequently Asked Questions
1
What is the severity of CVE-2022-45048?
CVE-2022-45048 is considered to be a high-severity vulnerability due to its potential for code execution.
2
How do I fix CVE-2022-45048?
To mitigate CVE-2022-45048, upgrade to Apache Ranger version 2.3.1 or later.
3
Who can exploit CVE-2022-45048?
Authenticated users with appropriate privileges can exploit CVE-2022-45048 by creating malicious policy expressions.
4
What versions of Apache Ranger are affected by CVE-2022-45048?
CVE-2022-45048 affects Apache Ranger version 2.3.0.
5
What impact does CVE-2022-45048 have on Apache Ranger installations?
The impact of CVE-2022-45048 is that it allows remote code execution, which could compromise the entire system.