In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94221 | vdb entry third party advisory |
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger | vendor advisory |