VYPR

Maven package

org.apache.knox/gateway-provider-identity-assertion-common

pkg:maven/org.apache.knox/gateway-provider-identity-assertion-common

Vulnerabilities (1)

  • CVE-2017-5646MedMay 26, 2017
    affected >= 0.2.0, < 0.12.0fixed 0.12.0

    For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit log