Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.
{ "vanir_signatures": [ { "id": "CVE-2018-11799-02802386", "signature_type": "Function", "digest": { "function_hash": "160194018468072020635403387757425004881", "length": 302.0 }, "target": { "file": "core/src/test/java/org/apache/oozie/action/hadoop/TestShellContentWriter.java", "function": "writeScript" }, "source": "https://github.com/apache/oozie/commit/352b76ebc9f5c3f548275214f1a29078622ab830", "signature_version": "v1", "deprecated": false }, { "id": "CVE-2018-11799-5bac1dbb", "signature_type": "Function", "digest": { "function_hash": "168159148419434136421736128982621231734", "length": 910.0 }, "target": { "file": "sharelib/oozie/src/main/java/org/apache/oozie/action/hadoop/ShellContentWriter.java", "function": "print" }, "source": "https://github.com/apache/oozie/commit/352b76ebc9f5c3f548275214f1a29078622ab830", "signature_version": "v1", "deprecated": false }, { "id": "CVE-2018-11799-64ef7fed", "signature_type": "Function", "digest": { "function_hash": "264970747429871551663195328184138576444", "length": 244.0 }, "target": { "file": "core/src/test/java/org/apache/oozie/action/hadoop/TestShellContentWriter.java", "function": "testMissingFile" }, "source": "https://github.com/apache/oozie/commit/352b76ebc9f5c3f548275214f1a29078622ab830", "signature_version": "v1", "deprecated": false }, { "id": "CVE-2018-11799-abbe06b3", "signature_type": "Line", "digest": { "line_hashes": [ "233246631065754539357421312588662251221", "295776024517750380090261865488681407365", "121819447314944507662208143820503064790", "285572287153155005233481418733062534817", "339882242034407000816010290823637190034", "81546773024659273036053770065409482347", "219824660516711567392605864520538268804", "98145750593739261586556647153234746200", "311910325282607174476351137980074695995", "172651663341236152387988707400589771309", "111095968980427487803250738284626427347", "251002249673703171680416722390289030638", "322546647638909165221269474226972646083", "32461531651547481647097425522581667031", "231685329752114104016313375756587344763", "163687871603659082352807640796016531980" ], "threshold": 0.9 }, "target": { "file": "sharelib/oozie/src/main/java/org/apache/oozie/action/hadoop/ShellContentWriter.java" }, "source": "https://github.com/apache/oozie/commit/352b76ebc9f5c3f548275214f1a29078622ab830", "signature_version": "v1", "deprecated": false }, { "id": "CVE-2018-11799-f2c973bc", "signature_type": "Line", "digest": { "line_hashes": [ "325683535220765380623283808865366175738", "66879726538751252127556043308924606450", "151019593348407694783823277815940564864", "309548290027564469889926410849180966533", "269274197580082869728296277736494913415", "54868532243595256360010527147784197970", "84847430953750215999702358987251061699", "12266625577712117940631813298745423004", "197696845149513557048264785260584648519", "199767383247030216428768509475147890840", "178208865892233296082273662609781839066", "28850267855991754428824947421678206287", "252254792962867012099763021370565955881", "270871632772676675570736611076465255434", "227832253040215488018985448982172058458" ], "threshold": 0.9 }, "target": { "file": "core/src/test/java/org/apache/oozie/action/hadoop/TestShellContentWriter.java" }, "source": "https://github.com/apache/oozie/commit/352b76ebc9f5c3f548275214f1a29078622ab830", "signature_version": "v1", "deprecated": false } ] }