Impact
An attacker could exploit Apache Ranger versions up to 2.8.0 by submitting a crafted request to the plugin-schema-registry component, which allows arbitrary class instantiation without proper validation. This flaw corresponds to the CWE-470 and CWE-94 weaknesses and permits the execution of arbitrary code with the same privileges as the Ranger service.
Affected Systems
Affected systems are installations of Apache Ranger 2.8.0 or earlier. The vulnerability is confined to the plugin-schema-registry component and does not affect newer releases such as 2.9.0 and above.
Risk and Exploitability
Specific exploitation details are not published, and no EPSS score is available. However, the nature of the vulnerability—allowing remote code execution—suggests a high severity impact. The vulnerability is not listed in the CISA KEV catalog, but the lack of an external exploit breakout does not mitigate the risk for environments still running vulnerable versions. Attackers would need network access to the Ranger service to submit malicious plugin definitions, likely through the REST API or configuration interfaces.
OpenCVE Enrichment