High severity8.4NVD Advisory· Published May 5, 2023· Updated Jun 17, 2026
CVE-2022-45048
CVE-2022-45048
Description
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.ranger:rangerMaven | >= 2.3.0, < 2.4.0 | 2.4.0 |
Affected products
3- Apache Software Foundation/Apache Rangerv5Range: 2.3.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-89gw-cffj-mqg9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-45048ghsaADVISORY
- lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6nvdMailing ListWEB
News mentions
0No linked articles in our index yet.