CVE-2017-15712
19.02.2018, 14:29
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.
Vendor | Product | Version |
---|---|---|
apache | oozie | 3.1.2 |
apache | oozie | 3.1.3 |
apache | oozie | 3.2 |
apache | oozie | 3.2.0 |
apache | oozie | 3.2.0:incubating |
apache | oozie | 3.3.0 |
apache | oozie | 3.3.0:rc0 |
apache | oozie | 3.3.0:rc1 |
apache | oozie | 3.3.1 |
apache | oozie | 3.3.1:rc0 |
apache | oozie | 3.3.1:rc1 |
apache | oozie | 3.3.2 |
apache | oozie | 3.3.2:rc0 |
apache | oozie | 4.0.0 |
apache | oozie | 4.0.0:rc0 |
apache | oozie | 4.0.0:rc1 |
apache | oozie | 4.0.0:rc3 |
apache | oozie | 4.0.1 |
apache | oozie | 4.0.1:rc0 |
apache | oozie | 4.0.1:rc1 |
apache | oozie | 4.1.0 |
apache | oozie | 4.1.0:rc0 |
apache | oozie | 4.1.0:rc1 |
apache | oozie | 4.2.0 |
apache | oozie | 4.2.0:rc0 |
apache | oozie | 4.3.0 |
apache | oozie | 4.3.0:rc0 |
apache | oozie | 4.3.0:rc1 |
apache | oozie | 5.0.0:beta1 |
𝑥
= Vulnerable software versions
References