oss-sec mailing list archives

CVE-2024-55532: Apache Ranger: Improper Neutralization of Formula Elements in a CSV File


From: Velmurugan Periasamy <vel () apache org>
Date: Mon, 03 Mar 2025 15:54:01 +0000

Severity: low

Affected versions:

- Apache Ranger through 2.5.0

Description:

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0.
Users are recommended to upgrade to version 2.6.0, which fixes this issue.

References:

https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger
https://ranger.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-55532


Current thread: