PT-2026-69429 · Apache · Apache Ranger
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Ranger versions prior to 2.9.0
Description
Remote Code Execution is possible through JDBC URL Injection. This occurs when an application fails to properly sanitize the JDBC URL, allowing an attacker to inject malicious parameters that can lead to the execution of arbitrary code on the server.
Recommendations
Upgrade to version 2.9.0.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Ranger