Apache Oozie Information Leakage Vulnerability (CVE-2017-15712)
Apache Oozie Information Leakage Vulnerability (CVE-2017-15712)
 
Release date:
Updated on:
Affected Systems:
 
Apache Group Oozie 5.0.0-beta1
Apache Group Oozie 3.1.3-4.3.0
 
Description:
  
Bugtraq id: 103102
CVE (CAN) ID: CVE-2017-15712
Apache Oozie is a harmonious workflow scheduling system that can manage Apache Hadoop jobs.
Apache Oozie 3.1.3-4.3.0 and 5.0.0-beta1 have security vulnerabilities. Attackers can exploit this vulnerability to obtain sensitive information.
<* Source: Daryn Sharp
*>
Suggestion:
  
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.apache.org/security/projects.html
Https://lists.apache.org/thread.html/4606709264fe7cb0285e2a12aca2d01a06b14cd58791c9fc32abd216@%3Cdev.oozie.apache.org%3E
 
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151206.htm