CVE-2017-7676: Apache Ranger

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.

Affected products

  • Apache Ranger: up to and including 0.7.0

Published 2017-06-14. Last modified 2026-06-17.