CVE-2024-45479

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*

History

28 May 2025, 20:43

Type Values Removed Values Added
CWE CWE-918
References () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - () https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/01/21/4 - () http://www.openwall.com/lists/oss-security/2025/01/21/4 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*
First Time Apache
Apache ranger

27 Jan 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
Summary
  • (es) Vulnerabilidad SSRF en la página Editar servicio de la interfaz de usuario de Apache Ranger en la versión 2.4.0 de Apache Ranger. Se recomienda a los usuarios que actualicen a la versión 2.5.0 de Apache Ranger, que soluciona este problema.

21 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 22:15

Updated : 2025-05-28 20:43


NVD link : CVE-2024-45479

Mitre link : CVE-2024-45479

CVE.ORG link : CVE-2024-45479


JSON object : View

Products Affected

apache

  • ranger
CWE
CWE-20

Improper Input Validation

CWE-918

Server-Side Request Forgery (SSRF)