| ID |
CVE-2017-15712
|
| Sažetak |
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host. |
| Reference |
|
| CVSS |
| Base: | 6.8 |
| Impact: | 6.9 |
| Exploitability: | 8.0 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| NETWORK |
LOW |
SINGLE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
NONE |
NONE |
|
| CVSS vektor |
AV:N/AC:L/Au:S/C:C/I:N/A:N |
| Zadnje važnije ažuriranje |
07-11-2023 - 02:40 |
| Objavljeno |
19-02-2018 - 14:29 |