Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
[
{
"signature_version": "v1",
"target": {
"file": "agents-common/src/test/java/org/apache/ranger/plugin/service/TestRangerBasePluginRaceCondition.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"250626262547175998193967617111369815384",
"103214457852052934613778605536008605507",
"134785959236107010958374731788908802087",
"175440381243969453587460920755272519669",
"18859480949395713816554981214543867079",
"184774791546709976688252981736292508467",
"167066144450572293146648775261197916640",
"193982641655409645484729959365622715876"
]
},
"source": "https://github.com/apache/ranger/commit/5c567041d56bf153a1c7fb320af42b4a9af673b0",
"signature_type": "Line",
"id": "CVE-2025-59059-d6312ad0",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-59059.json"