Impact
Missing authentication in the Apache Ranger download APIs allows unauthenticated users to retrieve plugin data on versions 2.8.0 and earlier. This weakness, identified as CWE-306, permits attackers to access potentially sensitive configuration and plugin information that could aid further exploitation. The impact is the unauthorized disclosure of internal data.
Affected Systems
Apache Ranger by the Apache Software Foundation, versions 2.8.0 and earlier.
Risk and Exploitability
The vulnerability does not have an EPSS score and is not listed in CISA KEV, indicating no publicly known exploits as of the latest data. The attack vector can be inferred as a network-based approach, where an attacker with network connectivity can issue HTTP requests to the download endpoints without authentication. Even though exploitation probability is unclear, the risk of sensitive data exposure with no authentication makes this issue significant, especially in environments where Ranger APIs are exposed to untrusted networks.
OpenCVE Enrichment