CRITICAL🇵🇱 Wersja polska

CVE-2024-55532

CVSS 9.8v3.1pub. 2025-03-03upd. 2025-05-21

Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.

🤖 AI Analysis
How it works

The vulnerability lies in the failure to properly neutralize so-called formula elements before placing data in the generated CSV file. A malicious user can introduce data into the system containing formulas or commands (e.g., starting with characters '=', '+', '-', '@'), which will be embedded in the exported CSV file. When a victim opens such a file in a spreadsheet application (e.g., Microsoft Excel, LibreOffice Calc), the application may automatically execute the contained formulas, including system commands or references to external resources.

Impact

An attacker can cause malicious code to be executed on the workstation of a victim who opens an infected CSV file, which may result in data theft, compromise of confidentiality, integrity, and availability of the user's resources.

Mitigation & patch

Apache Ranger should be updated to version 2.6.0 or later, which eliminates this vulnerability. Details are available on the vendor's website: https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger

Who is affected

Apache Ranger in all versions below 2.6.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Ranger

    APP
    Apache
    < 2.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-40920CRITICAL9.8same product

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended ...

CVE-2026-42537CRITICAL9.8same product

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to ver...

CVE-2026-32227CRITICAL9.8same product

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to up...

CVE-2026-28672CRITICAL9.8same product

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ra...

CVE-2026-44416CRITICAL9.8same product

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <...