First published: Wed Dec 19 2018(Updated: )
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Oozie | >=3.1.3<5.1.0 | |
Apache Oozie | =3.1.3-incubating |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11799 is considered a critical vulnerability due to the potential for user impersonation.
To fix CVE-2018-11799, upgrade Apache Oozie to version 5.1.0 or later.
CVE-2018-11799 can be exploited to enable a malicious user to impersonate other users through crafted XML workflows.
CVE-2018-11799 affects Apache Oozie versions from 3.1.3-incubating to 5.0.0.
No, user authentication alone is not sufficient to mitigate CVE-2018-11799; patching and updating the software are necessary.