Impact
The vulnerability allows an attacker to alter a URL parameter within Apache Ranger and, as a result, gain elevated privileges. By tampering with the request, the attacker can elevate their role to administrator or other privileged accounts, compromising confidentiality, integrity, and control over the Ranger deployment. This is a classic privilege escalation flaw as identified by CWE‑269 and CWE‑287.
Affected Systems
Apache Software Foundation’s Apache Ranger versions up to and including 2.8.0 are affected. Versions 2.9.0 and later contain the fix and are not impacted.
Risk and Exploitability
The exploit requires network access to the Ranger service and manipulation of an HTTP request sent to the server. Exact CVSS metrics are not publicly provided, and the EPSS score is currently unavailable, but the vulnerability is not listed in CISA’s KEV catalog. Given that the issue is a URL‑based privilege escalation, it is plausible that a remote attacker could easily abuse it without special conditions, making the risk significant for exposed services.
OpenCVE Enrichment