CVE-2018-11799: Apache Oozie
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.
Affected products
- Apache Oozie: from 3.1.3, before 5.1.0 (fixed in 5.1.0); version 3.1.3 only
Published 2018-12-19. Last modified 2026-06-17.