Apache Ranger Improper Neutralization of Formula Elements vulnerability

Description

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0.
Users are recommended to upgrade to version 2.6.0, which fixes this issue.

Basic information

Type
reviewed
Severity
low
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2025-03-03 18:31:28 UTC
Updated
2025-03-03 22:12:12 UTC
GitHub reviewed
2025-03-03 22:12:10 UTC
NVD published
2025-03-03

EPSS Score

Score Percentile
0.41% 61.54%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-1236 Improper Neutralization of Formula Elements in a CSV File

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven org.apache.ranger:security-admin-web < 2.6.0 2.6.0

References

cvelogic Threat Intelligence