PT-2020-12476 · Apache · Azkaban

N33Dle

+1

·

Published

2020-03-26

·

Updated

2020-03-31

·

CVE-2020-10992

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azkaban versions prior to 3.84.1
Description The issue allows XXE (XML External Entity) attacks, which is related to the XmlValidatorManager.java and XmlUserManager.java files in the validator and user directories, respectively. This can potentially lead to unauthorized access to sensitive data.
Recommendations For versions prior to 3.84.1, update to version 3.84.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the XmlValidatorManager and XmlUserManager classes until a patch is available. Avoid using external XML entities in the affected modules to minimize the risk of exploitation.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10992

Affected Products

Azkaban