First published: Tue Aug 29 2017(Updated: )
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Atlas | =0.6.0 | |
Apache Atlas | =0.6.0-rc1 | |
Apache Atlas | =0.6.0-rc2 | |
Apache Atlas | =0.7.0 | |
Apache Atlas | =0.7.0-rc1 | |
Apache Atlas | =0.7.0-rc2 | |
maven/org.apache.atlas:atlas-common | >=0.6.0-incubating<0.7.1-incubating | 0.7.1-incubating |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3153 is classified as a medium severity vulnerability due to its potential impact on the affected applications.
To fix CVE-2017-3153, you should upgrade Apache Atlas to version 0.7.1-incubating or later.
CVE-2017-3153 affects Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating.
CVE-2017-3153 is a Reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2017-3153 can be exploited through maliciously crafted search queries leading to the execution of arbitrary script code in the user's browser.