{"id":"CVE-2022-45048","details":"Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.\n\n\n","aliases":["GHSA-89gw-cffj-mqg9"],"modified":"2026-04-10T04:52:22.497266Z","published":"2023-05-05T08:15:09.080Z","references":[{"type":"ARTICLE","url":"https://lists.apache.org/thread/6rpzwy1smdhr60tsh1ydknn3kdm45bb6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/ranger","events":[{"introduced":"0"},{"last_affected":"ce3339c8ab653d99382caba9b2e5f306a7118561"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.3.0"}]}}],"versions":["ranger-0.4.0-rc0","ranger-0.6.0-rc1","release-2.1.0-rc0","release-2.2.0-rc0","release-2.2.0-rc1","release-2.2.0-rc2","release-2.3.0-rc0","release-2.3.0-rc1","release-2.3.0-rc2","release-2.3.0-rc3","release-ranger-2.1.0","release-ranger-2.2.0","release-ranger-2.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-45048.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}