https://seclists.org/oss-sec/2025/q1/38: CVE-2024-45479: Apache Ranger: SSRF in Edit Service page - Add logic to filter quests to localhost
Published Jan 21, 2025
·Updated
Affected Software
1 affected component
Apache Ranger<2.5.0
Frequently Asked Questions
1
What is the severity of CVE-2024-45479?
The severity of CVE-2024-45479 is classified as moderate.
2
Which versions of Apache Ranger are affected by CVE-2024-45479?
Apache Ranger versions 2.4.0 and earlier are affected by CVE-2024-45479.
3
How can I fix CVE-2024-45479?
To fix CVE-2024-45479, users should upgrade to Apache Ranger version 2.5.0 or later.
4
What type of vulnerability is CVE-2024-45479?
CVE-2024-45479 is a Server-Side Request Forgery (SSRF) vulnerability.
5
Where is the vulnerability CVE-2024-45479 located in Apache Ranger?
CVE-2024-45479 is located in the Edit Service page of the Apache Ranger UI.