Executive brief
Apache Ranger is an open-source data governance platform that manages access control and security policies across big data systems. A hostname verification vulnerability in the NiFiRegistryClient component allows attackers to potentially intercept and manipulate communications between Ranger and NiFi Registry through man-in-the-middle attacks, compromising the integrity of registry operations and policy enforcement.
Technical details
This vulnerability is a hostname verification bypass in the NiFiRegistryClient component of Apache Ranger. The issue affects versions 2.7.0 and earlier, allowing an attacker to intercept client-to-registry communications over TLS by presenting a certificate for a different hostname. The attack requires network access to intercept traffic (man-in-the-middle position) but does not require authentication. Attackers can potentially intercept, modify, or redirect registry communications. The fix is available in Apache Ranger version 2.8.0.
Affected products
- Apache Ranger 2.7.0 and earlier
Timeline
- 2026-03-03: disclosed
- 2026-03-03: patched: Fix available in version 2.8.0