Impact
Apache Ranger has a command‑injection flaw where the UNIX user‑group builder incorporates the supplied username directly into an operating‑system command without proper sanitization. An attacker who can supply a crafted username may cause the Ranger server to execute arbitrary shell commands, compromising confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑77 and is a classic example of improper neutralization of special elements.
Affected Systems
The vulnerability affects all released versions of Apache Ranger from 0.6 through 2.8, regardless of build or environment. Systems running these versions should verify their installation and determine whether the affected component is in use. 2.9 and later releases do not contain this flaw.
Risk and Exploitability
Although no EPSS score is available and the issue is not listed in the CISA KEV catalog, the potential for remote code execution makes the risk high. The likely attack vector is remote, via the Ranger REST interface or any client that can supply a username to the UnixUserGroupBuilder. Because the flaw permits arbitrary command execution, the impact is catastrophic if exploited. Immediate action is recommended to prevent an adversary from gaining control of the Ranger host.
OpenCVE Enrichment