Apache Ranger =< 0.5.2 allows to...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Apache Ranger =< 0.5.2 allows to download policy definitions without authentication through the following GET request: ``` http://<apache_ranger_IP>:6080/service/plugins/policies/download/<policy_name> ``` The prerequisite to exploit this flaw is to know (or guess) the policy name. This finding may not constitute a vulnerability by itself, but is equivalent to having access to a network filtering policy: finding holes in policies is then easier for an attacker.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息