Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Ranger — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Apache Ranger, with AI-generated Chinese analysis, references, and POCs.

Apache Ranger is an open-source project developed by the Apache Software Foundation that provides comprehensive security authorization for fine-grained access control across Hadoop components. This page aggregates publicly known vulnerabilities, misconfigurations, and security weaknesses associated with the Apache Ranger product line, covering incidents reported from its initial release through the present day. By organizing these records, the page enables security professionals and system administrators to effectively track vendor advisories and patch releases, gain a deeper understanding of specific weakness classes such as authentication bypasses or authorization flaws, and review the historical vulnerability profile of the product to assess long-term risk trends. The data includes details on impact severity, affected versions, and remediation strategies where available, allowing users to benchmark their current deployments against known security gaps. This resource is designed to support proactive risk management by providing a centralized view of security issues without requiring manual aggregation from multiple sources. Users can explore how specific vulnerabilities have evolved over time, identify patterns in reported exploits, and compare Apache Ranger’s security posture against other enterprise security frameworks. The information presented here is derived from official security advisories, community disclosures, and verified third-party reports to ensure accuracy and relevance for enterprise security planning.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-28672 Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder CWE-77--2026-08-10
CVE-2026-32227 Apache Ranger: SQL Injection vulnerability in lookup functionality CWE-89--2026-08-10
CVE-2026-40920 Apache Ranger: Privilege Escalation via URL Parameter CWE-269--2026-08-10
CVE-2026-42537 Apache Ranger: Remote Code Execution via JDBC URL Injection CWE-94--2026-08-10
CVE-2026-44416 Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation CWE-94--2026-08-10
CVE-2026-55799 Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator CWE-94--2026-08-10
CVE-2026-55814 Apache Ranger: Download APIs expose plugin data without authentication CWE-306--2026-08-10
CVE-2026-65942 Apache Ranger: Clients accept TLS certificates issued for other hostnames CWE-297--2026-08-10
CVE-2026-65945 Apache Ranger: Logs contain replayable JWT bearer tokens CWE-532--2026-08-10
CVE-2026-65948 Apache Ranger: UnixAuth lacks brute-force protection CWE-307--2026-08-10
CVE-2025-59060 Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient CWE-297 5.3AIMediumAI2026-03-03
CVE-2025-59059 Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator CWE-94 9.8AICriticalAI2026-03-03
CVE-2024-55532 Apache Ranger: Improper Neutralization of Formula Elements in a CSV File CWE-1236 9.8 -2025-03-03
CVE-2024-45479 Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost CWE-918 5.3 -2025-01-21
CVE-2024-45478 Apache Ranger: Stored XSS in Edit Service page - Add logic to validate user input CWE-79 5.4 -2025-01-21
CVE-2022-45048 Apache Ranger: code execution vulnerability in policy expressions CWE-74 8.4 High2023-05-05
CVE-2019-12397 Apache Ranger 跨站脚本漏洞 6.1 -2019-08-08
CVE-2018-11778 Apache Ranger 缓冲区错误漏洞 8.8 -2018-10-05
CVE-2016-6815 Apache Ranger 信任管理漏洞 6.5 -2017-10-13
CVE-2017-7677 Apache Ranger Hive Authorizer 安全漏洞 7.5 -2017-06-14
CVE-2017-7676 Apache Ranger Policy resource matcher 输入验证漏洞 9.1 -2017-06-14
CVE-2016-8751 Apache Ranger 跨站脚本漏洞 4.8 -2017-06-14
CVE-2016-8746 Apache Ranger 安全漏洞 5.9 -2017-06-14

All 23 known CVE vulnerabilities affecting Apache Ranger with full Chinese analysis, references, and POCs where available.