CVE-2018-11799

Publication date

2018-12-19 20:00:00

Family

apache

State

PUBLISHED

Description

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other users name.