Impact
Azkaban versions up to and including 4.0.0 contain a flaw in the ScheduleServlet fetchSchedule action where project permission checks are omitted. The flaw allows any authenticated user to supply a project and flow identifier and retrieve the corresponding schedule configuration. The data revealed includes timestamps, cron expressions, flow parameters, and notification email lists, representing a moderate to high confidentiality breach.
Affected Systems
Affected products include the Azkaban project’s Azkaban component. The vulnerability is present in all releases through version 4.0.0. No higher‑version fix details were provided in the input, so users should verify whether their deployment is beyond 4.0.0.
Risk and Exploitability
The CVSS score of 7.1 indicates medium severity. The EPSS score of 0.307% indicates a very low probability of exploitation, and the vulnerability is not listed in KEV, suggesting limited real‑world usage. The flaw is exploitable over the network via HTTP requests to the ScheduleServlet endpoint and requires only authenticated access. The attack vector is inferred to be remote due to the web‑based nature of the servlet.
OpenCVE Enrichment