Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45687
HistoryFeb 29, 2024 - 5:34 a.m.

XML External Entity

2024-02-2905:34:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
xml external entity
apache ambari
wfmanager
oozie workflow scheduler
file reading
privilege escalation

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

org.apache.ambari.contrib.views:wfmanager is vulnerable to XML External Entity (XXE) injection. The vulnerability is due to improper validation of user input, specifically within the Oozie Workflow Scheduler, allowing for root-level file reading and privilege escalation from low-privilege users.

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:45687