Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.
The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.
Link | Tags |
---|---|
https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger | vendor advisory |
http://www.openwall.com/lists/oss-security/2025/03/03/2 | mailing list third party advisory |