Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient
Severity: Low
Vendor: The Apache Software Foundation
Versions Affected: Apache Ranger versions prior to 2.8.0
Users affected: All users of ranger ranger
Description: Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient.  
Fix detail: Added logic to properly verify the hostname.  
Mitigation: Users should upgrade to 2.8.0 or later version of Apache Ranger with the fix.
Credit: Nikita Markevich <markevich.nikita1@gmail.com>

...