Maven package
org.apache.knox/gateway-provider-identity-assertion-common
pkg:maven/org.apache.knox/gateway-provider-identity-assertion-common
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-5646 | Med | 6.8 | >= 0.2.0, < 0.12.0 | 0.12.0 | May 26, 2017 | For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit log |
- affected >= 0.2.0, < 0.12.0fixed 0.12.0
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit log