CVE-2025-26796

CVE-2025-26796: Apache Oozie: XSS in Oozie Web Console

Vendor Apache Software Foundation
Product Apache Oozie
Weakness CWE-79 · XSS
Published March 22, 2025
Last update March 24, 2025

CVSS base score

What the vulnerability does

01Description

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Key dates

02Disclosure timeline

March 22, 2025 CVE published
March 24, 2025 Record updated

Related vulnerabilities

04Related CVE