Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 02:42
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://mail-archives.apache.org/mod_mbox/ranger-dev/201603.mbox/%3CD31EE434.14B879%25vel%40apache.org%3E - Vendor Advisory | 
Information
                Published : 2016-04-11 19:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-0735
Mitre link : CVE-2016-0735
CVE.ORG link : CVE-2016-0735
JSON object : View
Products Affected
                apache
- ranger
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
