First published: Tue Aug 29 2017(Updated: )
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Atlas | =0.6.0 | |
Apache Atlas | =0.6.0-rc1 | |
Apache Atlas | =0.6.0-rc2 | |
Apache Atlas | =0.7.0 | |
Apache Atlas | =0.7.0-rc1 | |
Apache Atlas | =0.7.0-rc2 | |
Apache Atlas | =0.7.1 | |
Apache Atlas | =0.7.1-rc1 | |
Apache Atlas | =0.7.1-rc2 | |
Apache Atlas | =0.7.1-rc3 | |
maven/org.apache.atlas:atlas-common | >=0.6.0-incubating<0.8-incubating | 0.8-incubating |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8752 has a medium severity rating due to unauthorized access to web application directory contents.
To fix CVE-2016-8752, upgrade to Apache Atlas version 0.8-incubating or later.
CVE-2016-8752 affects Apache Atlas versions 0.6.0, 0.7.0, and 0.7.1, including their release candidates.
The implications of CVE-2016-8752 include potential exposure of sensitive files in the webapp directory.
Yes, a patch is available in Apache Atlas version 0.8-incubating.