CVE-2017-3151: XSS
Published Aug 29, 2017
·Updated
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.
Affected Software
7 affected componentsFixes available
Apache Atlas=0.6.0-rc0
Apache Atlas=0.6.0-rc1
Apache Atlas=0.6.0-rc2
Apache Atlas=0.7.0-rc0
Apache Atlas=0.7.0-rc1
Apache Atlas=0.7.0-rc2
maven/org.apache.atlas:atlas-common>=0.6.0-incubating<0.7.1-incubating
0.7.1-incubating
Event History
Aug 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
May 13, 2022
Advisory Published
01:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-3151?
CVE-2017-3151 is considered a moderate severity vulnerability due to its potential for stored cross-site scripting.
2
How do I fix CVE-2017-3151?
To remediate CVE-2017-3151, upgrade Apache Atlas to version 0.7.1-incubating or later.
3
Which versions of Apache Atlas are affected by CVE-2017-3151?
CVE-2017-3151 affects Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating.
4
What type of vulnerability is CVE-2017-3151?
CVE-2017-3151 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Is CVE-2017-3151 being actively exploited?
There is no public information indicating active exploitation of CVE-2017-3151.