Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2025-59059
Critical
Low
Medium
High
Critical
9.8
CVSS Score
Vulnerability Description
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to version 2.8.0, which fixes this issue.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H
Known Affected Software
22 configuration(s) from 1 vendor(s)
ranger
Version:
1.0.0
CPE:
cpe:2.3:a:apache:ranger:1.0.0:rc1:*:*:*:*:*:*
ranger
Version:
0.5.3
CPE:
cpe:2.3:a:apache:ranger:0.5.3:rc3:*:*:*:*:*:*
ranger
Version:
2.5.0
CPE:
cpe:2.3:a:apache:ranger:2.5.0:-:*:*:*:*:*:*
ranger
Version:
0.6.2
CPE:
cpe:2.3:a:apache:ranger:0.6.2:rc1:*:*:*:*:*:*
ranger
Version:
2.1.0
CPE:
cpe:2.3:a:apache:ranger:2.1.0:-:*:*:*:*:*:*
ranger
Version:
0.6.0
CPE:
cpe:2.3:a:apache:ranger:0.6.0:rc1:*:*:*:*:*:*
ranger
Version:
1.1.0
CPE:
cpe:2.3:a:apache:ranger:1.1.0:rc2:*:*:*:*:*:*
ranger
Version:
2.3.0
CPE:
cpe:2.3:a:apache:ranger:2.3.0:-:*:*:*:*:*:*
ranger
Version:
0.6.3
CPE:
cpe:2.3:a:apache:ranger:0.6.3:-:*:*:*:*:*:*
ranger
Version:
0.4.0
CPE:
cpe:2.3:a:apache:ranger:0.4.0:rc3:*:*:*:*:*:*
ranger
Version:
0.5.1
CPE:
cpe:2.3:a:apache:ranger:0.5.1:rc2:*:*:*:*:*:*
ranger
Version:
0.5.0
CPE:
cpe:2.3:a:apache:ranger:0.5.0:rc3:*:*:*:*:*:*
ranger
Version:
2.0.0
CPE:
cpe:2.3:a:apache:ranger:2.0.0:rc1:*:*:*:*:*:*
ranger
Version:
2.2.0
CPE:
cpe:2.3:a:apache:ranger:2.2.0:-:*:*:*:*:*:*
ranger
Version:
0.7.1
CPE:
cpe:2.3:a:apache:ranger:0.7.1:rc1:*:*:*:*:*:*
ranger
Version:
0.6.1
CPE:
cpe:2.3:a:apache:ranger:0.6.1:rc2:*:*:*:*:*:*
ranger
Version:
0.4.1
CPE:
cpe:2.3:a:apache:ranger:0.4.1:rc1:*:*:*:*:*:*
ranger
Version:
0.5.2
CPE:
cpe:2.3:a:apache:ranger:0.5.2:rc1:*:*:*:*:*:*
ranger
Version:
0.7.0
CPE:
cpe:2.3:a:apache:ranger:0.7.0:-:*:*:*:*:*:*
ranger
Version:
2.4.0
CPE:
cpe:2.3:a:apache:ranger:2.4.0:-:*:*:*:*:*:*
ranger
Version:
1.2.0
CPE:
cpe:2.3:a:apache:ranger:1.2.0:rc1:*:*:*:*:*:*
ranger
Version:
2.6.0
CPE:
cpe:2.3:a:apache:ranger:2.6.0:-:*:*:*:*:*:*
This vulnerability affects 22 software configuration(s). Ensure you patch all affected systems.
Severity Details
9.8
out of 10.0
Critical
Weakness Type (CWE)
CWE-94
Top 25 #7
Improper Control of Generation of Code ('Code Injection')
- Description
- The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
- Exploit Likelihood
- Medium
- Typical Severity
- High
- OWASP Top 10
- A03:2021-Injection
- Abstraction Level
- Base
Key Information
- Published Date
- March 03, 2026
