Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 03 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue. | |
| Title | Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient | |
| Weaknesses | CWE-297 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-03-03T11:14:18.408Z
Reserved: 2025-09-08T18:55:29.925Z
Link: CVE-2025-59060
No data.
Status : Received
Published: 2026-03-03T11:16:14.853
Modified: 2026-03-03T12:16:06.770
Link: CVE-2025-59060
No data.
OpenCVE Enrichment
No data.
Weaknesses