CVE-2025-26796
- EPSS 0.21%
- Veröffentlicht 22.03.2025 12:23:19
- Zuletzt bearbeitet 01.04.2025 20:27:46
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release...
CVE-2025-23195
- EPSS 0.13%
- Veröffentlicht 21.01.2025 22:15:12
- Zuletzt bearbeitet 09.06.2025 19:36:09
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without d...
CVE-2020-35451
- EPSS 0.1%
- Veröffentlicht 09.03.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:18
There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation.
CVE-2018-11799
- EPSS 0.24%
- Veröffentlicht 19.12.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:03
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.
CVE-2017-15712
- EPSS 0.66%
- Veröffentlicht 19.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:03
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference...