原始 OSV JSON{
"id": "GHSA-j84c-j8qm-g47r",
"aliases": [
"CVE-2016-0733"
],
"details": "The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.",
"summary": "The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.5.1"
}
]
}
],
"package": {
"name": "org.apache.ranger:ranger",
"ecosystem": "Maven"
}
}
],
"modified": "2022-04-27T13:41:39Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"published": "2018-10-17T17:21:11Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-0733",
"type": "ADVISORY"
},
{
"url": "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
"type": "WEB"
},
{
"url": "https://github.com/advisories/GHSA-j84c-j8qm-g47r",
"type": "ADVISORY"
},
{
"url": "https://issues.apache.org/jira/browse/RANGER-835",
"type": "WEB"
},
{
"url": "https://mail-archives.apache.org/mod_mbox/ranger-dev/201602.mbox/%3CD2D9A4C5.114ECA%[email protected] %3E",
"type": "WEB"
},
{
"url": "http://www.securityfocus.com/bid/82871",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "CRITICAL",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T21:42:33Z"
}
}