Users are recommended to upgrade to version 2.8.0, which fixes this issue.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c87w-642h-m97h | Apache Ranger has a Code Injection vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache ranger |
|
| Vendors & Products |
Apache
Apache ranger |
Tue, 03 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 03 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 03 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | |
| Title | Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator | |
| Weaknesses | CWE-94 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-03-03T14:54:30.232Z
Reserved: 2025-09-08T18:36:43.801Z
Link: CVE-2025-59059
Updated: 2026-03-03T11:14:16.410Z
Status : Awaiting Analysis
Published: 2026-03-03T11:16:14.547
Modified: 2026-03-03T21:52:29.877
Link: CVE-2025-59059
No data.
OpenCVE Enrichment
Updated: 2026-03-04T14:54:26Z
Github GHSA