CVE-2017-15712
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 2.5%
probabilidade de exploração
2.5%top 16% das CVEs
exploração observada
nãonenhuma fonte reporta
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.
Produtos afetados
Apache Software Foundation · Apache Oozie