← All CVEs

CVE-2024-45479

critical · 9.1

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

9.1
CVSS
0.6%
EPSS (exploit prob.)
49th
EPSS percentile
2025-01-21
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-918

Affected products

VendorProductAffected versions
apacheranger>= 2.4.0, < 2.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-45479