Impact
An attacker could exploit Apache Ranger versions up to 2.8.0 by submitting a crafted request to the plugin-schema-registry component, which allows arbitrary class instantiation without proper validation. This flaw corresponds to the CWE-470 and CWE-94 weaknesses and permits the execution of arbitrary code with the same privileges as the Ranger service.
Affected Systems
Affected systems are installations of Apache Ranger 2.8.0 or earlier. The vulnerability is confined to the plugin-schema-registry component and does not affect newer releases such as 2.9.0 and above.
Risk and Exploitability
Specific exploitation details are not published, but the CVSS score of 9.8 marks it as critical. The EPSS score is below 1%, indicating the likelihood of exploitation is currently low, though the risk remains high because the flaw allows remote code execution. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access to the Ranger REST API to submit malicious plugin definitions, likely through the plugin-schema-registry endpoint, and could instantiate arbitrary classes with Ranger service privileges.
OpenCVE Enrichment