Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.
{
"severity": "MODERATE",
"github_reviewed_at": "2020-06-16T22:00:20Z",
"cwe_ids": [
"CWE-20"
],
"github_reviewed": true,
"nvd_published_at": null
}