CVE-2024-45479
Apache Ranger UI vulnerable to Server Side Request Forgery
9.1
CRITICAL
CVSS 3.1
EPSS 0.29%
Description
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
How to fix CVE-2024-45479
To remediate CVE-2024-45479, upgrade the affected package to a fixed version below.
- Maven/org.apache.ranger:ranger—upgrade to 2.5.0 or later
Is CVE-2024-45479 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.5.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |