Ranger

Vendor:

First CVE: Apr 11, 2016 · Active for 10 years

21
Total CVEs
More Total CVEs than 94% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ranger over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2016
10 years ago
Most Recent CVE
Mar 3, 2026
143 days ago

CVE Severity & Scoring

Ranger21 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None16 (76.2%)
Unknown0 (0.0%)
Required5 (23.8%)
Privileges Required
Low7 (33.3%)
High4 (19.0%)
None10 (47.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes thi
Mar 3, 20269.833NONO
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.
Jun 14, 20179.830NONO
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.
Oct 5, 20188.829NONO
The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveragi
Apr 12, 20169.828NONO
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes
Mar 3, 20259.827NONO
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users
May 5, 20238.827NONO
An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on a database can alter the owners
May 5, 20238.126NONO
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
Jan 21, 20259.124NONO
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime pa
Jun 13, 20167.224NONO
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.
Apr 11, 20167.123NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Ranger

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.018.81.1%00
0.6.116.52.1%00
0.6.025.72.1%00
0.5.325.72.1%00
0.5.236.22.0%00
0.5.146.81.9%00
0.5.037.51.9%00
0.4.016.52.1%00