MAVEN · JANUARY 2025 · EARLY WARNING

Apache Ranger UI SSRF Vulnerability: Early Warning and Mitigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
org.apache.ranger:ranger (maven)
Affected versions
>= 0.5.0, < 0.5.2 or < 0.5.3 or < 0.7.1 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or < 0.5.0 or < 0.5.0 or >= 2.3.0, < 2.4.0 or >= 2.3.0, <= 2.3.0 or < 1.2.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or < 0.7.1 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.0, < 2.0.0 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.0, <= 1.2.0 or < 2.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.0, <= 1.2.0 or >= 2.0.0, <= 2.0.0 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.3.0, <= 2.3.0 or >= 2.4.0, <= 2.4.0 or < 0.5.1 or < 0.5.1 or < 0.6.1 or >= 0.6.0, <= 0.6.0 or < 0.6.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or < 0.6.2 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or < 2.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.0, <= 1.2.0 or >= 2.0.0, <= 2.0.0 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.3.0, <= 2.3.0 or >= 2.4.0, <= 2.4.0
Patched version
2.5.0
GHSA-G9GF-G5JQ-9H3V

An early warning has been issued for a critical Server Side Request Forgery (SSRF) vulnerability in Apache Ranger UI, specifically affecting version 2.4.0. Users are advised to take immediate action.

What happened

An early warning indicates a critical Server Side Request Forgery (SSRF) vulnerability in the Apache Ranger UI, specifically within the Edit Service Page of version 2.4.0. This vulnerability, tracked as GHSA-G9GF-G5JQ-9H3V, allows for potential SSRF attacks. The issue is reportedly fixed in Apache Ranger version 2.5.0. Users of affected versions are recommended to upgrade to mitigate this risk.

The affected versions include a complex range of Apache Ranger releases. Specifically, versions greater than or equal to 0.5.0 and less than 2.5.0 are reportedly vulnerable. The patched version that addresses this vulnerability is Apache Ranger 2.5.0. It is crucial for users to review their current versions against this range to assess their exposure.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If org.apache.ranger:ranger is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Apache Ranger versions greater than or equal to 0.5.0 and less than 2.5.0.

What should I do right now?

Check your current version of Apache Ranger and upgrade to version 2.5.0 if you are within the affected range.

Is there an official fix available?

Yes, Apache Ranger version 2.5.0 is the patched version that fixes this vulnerability.

Should I wait for further confirmation before acting?

While this is an early warning, it is recommended to take immediate action by checking your version and planning an upgrade to mitigate potential risks.

Sources

Join the 0Day waitlist →

← Back to all threats