Severity
High
Analysis Summary
CVE-2025-59060 CVSS:5.3
Apache Ranger could allow a remote attacker to bypass hostname verification, caused by a hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient. This allows an attacker to bypass intended hostname verification.
CVE-2025-59059 CVSS:9.8
Apache Ranger could allow a remote attacker to execute arbitrary code on the system, caused by a remote code execution Vulnerability in NashornScriptEngineCreator.
Impact
- Security Bypass
- Code Execution
Indicators of Compromise
CVE
CVE-2025-59060
CVE-2025-59059
Affected Vendors
Apache
Affected Products
- Apache Software Foundation Apache Ranger 2.7.0
- Apache Ranger 2.7.0
Remediation
Upgrade to the latest version, available from the Apache Website.