There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 34.7%