SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
History

Mon, 27 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 22:30:00 +0000

Type Values Removed Values Added
References

Tue, 21 Jan 2025 21:45:00 +0000

Type Values Removed Values Added
Description SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
Title Apache Ranger: SSRF in Edit Service page - Add logic to filter requests to localhost
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-01-27T21:06:38.671Z

Reserved: 2024-08-29T14:51:06.723Z

Link: CVE-2024-45479

cve-icon Vulnrichment

Updated: 2025-01-21T22:02:49.988Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-01-21T22:15:12.290

Modified: 2025-01-27T21:15:13.410

Link: CVE-2024-45479

cve-icon Redhat

No data.