PT-2026-69437 · Apache · Apache Ranger
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Ranger Client Code versions prior to 2.9.0
Description
An issue exists in the client code where TLS hostname verification is not properly performed. TLS (Transport Layer Security) hostname verification is a process that ensures the server the client is connecting to is actually the server it claims to be by verifying the hostname in the certificate.
Recommendations
Upgrade to version 2.9.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Ranger