cbcvebase.
CVE-2017-15712
published 2018-02-19

CVE-2017-15712: Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user…

medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.

Affected

15 ranges
VendorProductVersion rangeFixed in
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apacheoozie
apache_software_foundationapache_oozie
apache_software_foundationapache_oozie