Apache Ranger Improper Neutralization of Formula Elements in CSV Export Vulnerability

Vulnerability

A vulnerability exists in the Export to CSV feature of Apache Ranger, in versions prior to 2.6.0, due to improper neutralization of formula elements. This issue could potentially be exploited by manipulating the exported content.

Impact

Exploitation of this vulnerability could lead to unintended execution of formulas when the CSV file is opened, potentially causing malicious actions to be performed automatically.

Remediation

Users are advised to upgrade to Apache Ranger version 2.6.0 or later, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.4
exploitability
6.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.