oss-sec mailing list archives
CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator
From: Velmurugan Periasamy <vel () apache org>
Date: Mon, 02 Mar 2026 20:21:12 +0000
Severity: low Affected versions: - Apache Ranger through 2.7.0 Description: Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. Credit: chengtianyi <chengtianyi () huawei com> (finder) References: https://ranger.apache.org/ https://www.cve.org/CVERecord?id=CVE-2025-59059
Current thread:
- CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator Velmurugan Periasamy (Mar 02)
