{"id":"GHSA-2h4w-p9fh-9rmv","summary":"Apache Ranger Improper Neutralization of Formula Elements vulnerability","details":"Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version \u003c 2.6.0.\nUsers are recommended to upgrade to version 2.6.0, which fixes this issue.","aliases":["CVE-2024-55532"],"modified":"2025-03-03T22:42:09.973197Z","published":"2025-03-03T18:31:28Z","database_specific":{"cwe_ids":["CWE-1236"],"github_reviewed_at":"2025-03-03T22:12:10Z","severity":"LOW","github_reviewed":true,"nvd_published_at":"2025-03-03T16:15:38Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55532"},{"type":"WEB","url":"https://github.com/apache/ranger/commit/8d89fec991f05bd92e28f459bc2b3a3024aaad82"},{"type":"WEB","url":"https://cwiki.apache.org/confluence/display/RANGER/Apache+Ranger+2.6.0+-+Release+Notes"},{"type":"WEB","url":"https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger"},{"type":"PACKAGE","url":"https://github.com/apache/ranger"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/RANGER-5015"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/03/2"}],"affected":[{"package":{"name":"org.apache.ranger:security-admin-web","ecosystem":"Maven","purl":"pkg:maven/org.apache.ranger/security-admin-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0"}]}],"versions":["0.6.0","0.6.1","0.6.2","0.6.3","0.7.0","0.7.1","1.0.0","1.1.0","1.2.0","2.0.0","2.1.0","2.2.0","2.3.0","2.4.0","2.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-2h4w-p9fh-9rmv/GHSA-2h4w-p9fh-9rmv.json"}}],"schema_version":"1.7.3"}