CVE-2024-45479
critical · 9.1SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
9.1
CVSS
0.6%
EPSS (exploit prob.)
49th
EPSS percentile
2025-01-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-918
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | ranger | >= 2.4.0, < 2.5.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-45479