Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
BID:103102
CVE-2017-15712 |Info
Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
| Bugtraq ID: | 103102 |
| Class: | Design Error |
| CVE: |
CVE-2017-15712 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2018 12:00AM |
| Updated: | Feb 15 2018 12:00AM |
| Credit: | Daryn Sharp and Jason Lowe of Oath. |
| Vulnerable: |
Apache Oozie 4.3 Apache Oozie 5.0.0-Beta1 Apache Oozie 3.1.3-Incubating |
| Not Vulnerable: |
Apache Oozie 4.3.1 |
Discussion
Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
Apache Oozie is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
Apache Oozie 3.1.3-incubating through Oozie 4.3.0 and 5.0.0-beta1 are vulnerable.
Apache Oozie is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
Apache Oozie 3.1.3-incubating through Oozie 4.3.0 and 5.0.0-beta1 are vulnerable.
Exploit / POC
Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Oozie CVE-2017-15712 Information Disclosure Vulnerability
References:
References:
- Apache Oozie Home page (Apache)
- Apache Oozie Server vulnerability (Apache)