CVE-2017-5646
Last modified
CVE-2017-5646 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this activity is audit logged and can be easily associated with the authenticated user, this is still a serious security issue. All users are recommended to upgrade to the Apache Knox 0.12.0 release.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Knox | 0.2.0 |
| Apache | Knox | 0.3.0 |
| Apache | Knox | 0.4.0 |
| Apache | Knox | 0.5.0 |
| Apache | Knox | 0.6.0 |
| Apache | Knox | 0.7.0 |
| Apache | Knox | 0.8.0 |
| Apache | Knox | 0.9.0 |
| Apache | Knox | 0.10.0 |
| Apache | Knox | 0.11.0 |
References
- http://www.securityfocus.com/bid/98739Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98739Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5646?
How severe is CVE-2017-5646?
How do I fix CVE-2017-5646?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5640It was noticed that a malicious process impersonating an Imp…
- CVE-2017-5641Previous versions of Apache Flex BlazeDS (4.7.2 and earlier)…9.8
- CVE-2017-5642During installation of Ambari 2.4.0 through 2.4.2, Ambari Se…
- CVE-2017-5643Apache Camel's Validation Component is vulnerable against SS…
- CVE-2017-5644Apache POI in versions prior to release 3.15 allows remote a…
- CVE-2017-5645In Apache Log4j 2.x before 2.8.2, when using the TCP socket …9.8
- CVE-2017-5647A bug in the handling of the pipelined requests in Apache To…
- CVE-2017-5648While investigating bug 60718, it was noticed that some call…
- CVE-2017-5649Apache Geode before 1.1.1, when a cluster has enabled securi…
- CVE-2017-5650In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, …
- CVE-2017-5651In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, …
- CVE-2017-5652During a routine security analysis, it was found that one of…
Are you affected by CVE-2017-5646?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
