CVE-2017-3150: XSS
Published Aug 29, 2017
·Updated
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.
Affected Software
7 affected componentsFixes available
Apache Atlas=0.6.0
Apache Atlas=0.6.0-rc1
Apache Atlas=0.6.0-rc2
Apache Atlas=0.7.0
Apache Atlas=0.7.0-rc1
Apache Atlas=0.7.0-rc2
maven/org.apache.atlas:atlas-common>=0.6.0-incubating<0.7.1-incubating
0.7.1-incubating
Event History
Aug 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
May 17, 2022
Advisory Published
01:18 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-3150?
CVE-2017-3150 is classified as a medium severity vulnerability due to its potential to expose sensitive data.
2
How do I fix CVE-2017-3150?
To fix CVE-2017-3150, upgrade to Apache Atlas version 0.7.1-incubating or later.
3
What impact does CVE-2017-3150 have on my system?
CVE-2017-3150 may allow client-side scripts to access cookies, which could jeopardize user session security.
4
Which versions of Apache Atlas are affected by CVE-2017-3150?
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating are affected by CVE-2017-3150.
5
Is there a workaround for CVE-2017-3150?
There is no documented workaround for CVE-2017-3150; upgrading to the patched version is recommended.