The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.
{ "nvd_published_at": "2016-04-11T19:59:00Z", "cwe_ids": [ "CWE-639", "CWE-863" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-04-14T20:49:35Z" }