Description
Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Problem types
CWE-297 Improper Validation of Certificate with Host Mismatch
Product status
Any version
Credits
Nikita Markevich <markevich.nikita1@gmail.com>
References
www.openwall.com/lists/oss-security/2026/03/02/4
lists.apache.org/thread/c4plx81z3xs86vgl3fd95y3q7hhtff05