Apache Ranger UI SSRF Vulnerability: Early Warning and Mitigation
- Severity
- HIGH
- Affected component
- org.apache.ranger:ranger (maven)
- Affected versions
- >= 0.5.0, < 0.5.2 or < 0.5.3 or < 0.7.1 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or < 0.5.0 or < 0.5.0 or >= 2.3.0, < 2.4.0 or >= 2.3.0, <= 2.3.0 or < 1.2.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or < 0.7.1 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.0, < 2.0.0 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.0, <= 1.2.0 or < 2.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.0, <= 1.2.0 or >= 2.0.0, <= 2.0.0 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.3.0, <= 2.3.0 or >= 2.4.0, <= 2.4.0 or < 0.5.1 or < 0.5.1 or < 0.6.1 or >= 0.6.0, <= 0.6.0 or < 0.6.3 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or < 0.6.2 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or < 2.5.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.7.0, <= 0.7.0 or >= 0.7.1, <= 0.7.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.0, <= 1.2.0 or >= 2.0.0, <= 2.0.0 or >= 2.1.0, <= 2.1.0 or >= 2.2.0, <= 2.2.0 or >= 2.3.0, <= 2.3.0 or >= 2.4.0, <= 2.4.0
- Patched version
- 2.5.0
An early warning has been issued for a critical Server Side Request Forgery (SSRF) vulnerability in Apache Ranger UI, specifically affecting version 2.4.0. Users are advised to take immediate action.
What happened
An early warning indicates a critical Server Side Request Forgery (SSRF) vulnerability in the Apache Ranger UI, specifically within the Edit Service Page of version 2.4.0. This vulnerability, tracked as GHSA-G9GF-G5JQ-9H3V, allows for potential SSRF attacks. The issue is reportedly fixed in Apache Ranger version 2.5.0. Users of affected versions are recommended to upgrade to mitigate this risk.
The affected versions include a complex range of Apache Ranger releases. Specifically, versions greater than or equal to 0.5.0 and less than 2.5.0 are reportedly vulnerable. The patched version that addresses this vulnerability is Apache Ranger 2.5.0. It is crucial for users to review their current versions against this range to assess their exposure.
What to do about it
- Immediately check your current version of Apache Ranger against the affected version range.
- If your version is within the affected range, plan and execute an upgrade to Apache Ranger 2.5.0 as soon as possible.
- Monitor the primary sources for any updates or additional information regarding this vulnerability.
- Consider implementing additional security measures to protect against SSRF attacks while the upgrade is being prepared.
- Communicate this vulnerability and the planned mitigation steps to your team and stakeholders to ensure awareness and cooperation.
How 0Day would have caught this
org.apache.ranger:ranger is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using Apache Ranger versions greater than or equal to 0.5.0 and less than 2.5.0.
What should I do right now?
Check your current version of Apache Ranger and upgrade to version 2.5.0 if you are within the affected range.
Is there an official fix available?
Yes, Apache Ranger version 2.5.0 is the patched version that fixes this vulnerability.
Should I wait for further confirmation before acting?
While this is an early warning, it is recommended to take immediate action by checking your version and planning an upgrade to mitigate potential risks.