CVE Published: 19/02/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2017 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Oozie Status : PUBLISHED
CVE-2017-15712 Description
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.