← Back

CVE-2017-15712

nvd nist
Published: Feb 19, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.

Affected (29)

Products: Apache: Oozie
1 product
Oozie
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 3.1.2
Version 3.1.3
Version 3.2.0
Version 3.2.0 incubating
Version 3.2
Version 3.3.0
Version 3.3.0 rc0
Version 3.3.0 rc1
Version 3.3.1
Version 3.3.1 rc0
Version 3.3.1 rc1
Version 3.3.2
Version 3.3.2 rc0
Version 4.0.0
Version 4.0.0 rc0
Version 4.0.0 rc1
Version 4.0.0 rc3
Version 4.0.1
Version 4.0.1 rc0
Version 4.0.1 rc1
Version 4.1.0
Version 4.1.0 rc0
Version 4.1.0 rc1
Version 4.2.0
Version 4.2.0 rc0
Version 4.3.0
Version 4.3.0 rc0
Version 4.3.0 rc1
Version 5.0.0 beta1

Timeline

No history available yet.