CVE-2017-15712

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
apacheoozie
3.1.2
apacheoozie
3.1.3
apacheoozie
3.2
apacheoozie
3.2.0
apacheoozie
3.2.0:incubating
apacheoozie
3.3.0
apacheoozie
3.3.0:rc0
apacheoozie
3.3.0:rc1
apacheoozie
3.3.1
apacheoozie
3.3.1:rc0
apacheoozie
3.3.1:rc1
apacheoozie
3.3.2
apacheoozie
3.3.2:rc0
apacheoozie
4.0.0
apacheoozie
4.0.0:rc0
apacheoozie
4.0.0:rc1
apacheoozie
4.0.0:rc3
apacheoozie
4.0.1
apacheoozie
4.0.1:rc0
apacheoozie
4.0.1:rc1
apacheoozie
4.1.0
apacheoozie
4.1.0:rc0
apacheoozie
4.1.0:rc1
apacheoozie
4.2.0
apacheoozie
4.2.0:rc0
apacheoozie
4.3.0
apacheoozie
4.3.0:rc0
apacheoozie
4.3.0:rc1
apacheoozie
5.0.0:beta1
𝑥
= Vulnerable software versions