Impact
Apache Ranger’s GraalScriptEngineCreator, used for executing scripts within policies, contains a flaw that allows an attacker to inject arbitrary code. By manipulating the script engine during policy deployment or execution, an adversary can run commands with the Ranger process’s privileges, leading to full compromise of the system. This weakness is classified as CWE‑94, indicating an improper control of code generation.
Affected Systems
Apache Ranger versions 2.8.0 and earlier are affected. The flaw exists in all releases up to and including 2.8.0. Users should upgrade to version 2.9.0, which contains the necessary fix, as recommended by the vendor.
Risk and Exploitability
The remote code execution nature of this flaw makes it a high‑severity issue. Although the EPSS score is unavailable and the vulnerability is not yet listed in the KEV catalog, the potential impact warrants urgent attention. Exploitation would likely occur over the network by submitting crafted scripts or policy definitions to the Ranger server, so restricting network exposure and enforcing strict authentication on policy changes can mitigate risk while a patch is applied.
OpenCVE Enrichment