← Back to CVE List

CVE-2017-15712

Published: 2018-02-19T14:29Z
Last Modified: 2024-11-21T03:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt