CVE-2017-15712: Apache Oozie
Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.
Affected products
- Apache Oozie: version 3.1.2 only; version 3.1.3 only; version 3.2 only; version 3.2.0 only; version 3.3.0 only; version 3.3.1 only; …
Published 2018-02-19. Last modified 2026-06-17.