Impact
The described flaw enables an attacker to inject an arbitrary JDBC URL into Apache Ranger, leading to remote code execution. The vulnerability stems from insufficient input validation on JDBC URL strings, allowing an attacker to embed executable code. Successful exploitation would allow the attacker to run arbitrary commands on the underlying system, compromising confidentiality, integrity and availability.
Affected Systems
Apache Ranger versions 2.8.0 and earlier are affected. The vendor is Apache Software Foundation, product Apache Ranger. No specific patch level is mentioned beyond version 2.8.0. The recommended fix is to upgrade to 2.9.0 or any later release.
Risk and Exploitability
No CVSS score is provided in the CVE record, but the vulnerability is a classic remote code execution flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker inserting a malicious JDBC URL via a configuration or API request that Ranger processes without proper validation, enabling arbitrary code execution.
OpenCVE Enrichment