Impact
Apache Ranger logs can contain JWT bearer tokens that are replayable. Those tokens captured in log files allow an attacker who reads them to extract an authentication token and reuse it to impersonate a user, granting unauthorized access to Ranger resources. The weakness is logging of sensitive information, classified as CWE‑532.
Affected Systems
The problem affects Apache Ranger versions up through 2.8.0. Versions newer than 2.8.0, specifically 2.9.0, contain the fix. The product is developed by the Apache Software Foundation.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so the precise exploitation probability is unclear. Nevertheless, the presence of clear‑text, replayable tokens in logs represents a high‑severity risk if an adversary can read the log files. Likely attack vectors include anyone who gains privileged access to the Ranger log directory or a compromised system exposing logs externally. Once a token is obtained, it can be replayed in subsequent API calls to achieve authenticated access.
OpenCVE Enrichment