CVE-2018-11799: Apache Oozie

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.

Affected products

  • Apache Oozie: from 3.1.3, before 5.1.0 (fixed in 5.1.0); version 3.1.3 only

Published 2018-12-19. Last modified 2026-06-17.