CVE-2017-3152: XSS
Published Aug 29, 2017
·Updated
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
Affected Software
7 affected componentsFixes available
Apache Atlas=0.6.0
Apache Atlas=0.6.0-rc1
Apache Atlas=0.6.0-rc2
Apache Atlas=0.7.0
Apache Atlas=0.7.0-rc1
Apache Atlas=0.7.0-rc2
maven/org.apache.atlas:atlas-common>=0.6.0-incubating<0.7.1-incubating
0.7.1-incubating
Event History
Aug 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
May 17, 2022
Advisory Published
via GitHub·01:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-3152?
CVE-2017-3152 is categorized as a moderate severity vulnerability due to the potential impact of DOM-based cross-site scripting.
2
How do I fix CVE-2017-3152?
To remediate CVE-2017-3152, upgrade Apache Atlas to version 0.7.1-incubating or later.
3
What versions of Apache Atlas are affected by CVE-2017-3152?
CVE-2017-3152 affects Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating.
4
What kind of vulnerability is CVE-2017-3152?
CVE-2017-3152 is a DOM-based cross-site scripting (XSS) vulnerability found in the edit-tag functionality.
5
Who should be concerned about CVE-2017-3152?
Organizations using Apache Atlas versions 0.6.0 or 0.7.0 should be concerned about CVE-2017-3152 due to the risk of XSS attacks.