Open Source Security mailing list@oss_securityGeneral
Apache Ranger hosts two low‑severity issues: a hostname verification bypass in NiFiRegistryClient/NifiClient and a remote code execution in NashornScriptEngineCreator; no POC, exploit, patch, or active use details are provided.
CCB Alert@CCBalertDisclosure
This message announces the CVE‑2025‑59059 critical vulnerability in Apache Ranger, highlighting its remote code execution risk, CVSS score of 9.8, and urging users to apply the patch.
CVE@CVEnewPatch
Apache Ranger versions <=2.7.0 are vulnerable to a remote code execution flaw; users should upgrade to 2.8.0 to remediate.
The Hacker Wire@TheHackerWirePatch
The post announces a critical RCE vulnerability in Apache Ranger’s NashornScriptEngineCreator and advises users to upgrade to version 2.8.0 to remediate the issue.
The Hacker Wire@TheHackerWirePatch
The post announces a critical RCE vulnerability in Apache Ranger’s NashornScriptEngineCreator and advises users to upgrade to version 2.8.0 to remediate the issue.
The Hacker Wire@TheHackerWirePatch
The post announces a critical RCE vulnerability in Apache Ranger’s NashornScriptEngineCreator and advises users to upgrade to version 2.8.0 to remediate the issue.
Infoflowcloud@infoflowcloudPatch
Apache Ranger versions up to 2.7.0 contain a remote code execution flaw in NashornScriptEngineCreator; users are advised to upgrade to 2.8.0 to remediate the issue.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text only lists the CVE ID and a link to a vulnerability details page, with no additional information.