CVE-2017-3153: XSS
Published Aug 29, 2017
·Updated
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
Affected Software
7 affected componentsFixes available
Apache Atlas=0.6.0
Apache Atlas=0.6.0-rc1
Apache Atlas=0.6.0-rc2
Apache Atlas=0.7.0
Apache Atlas=0.7.0-rc1
Apache Atlas=0.7.0-rc2
maven/org.apache.atlas:atlas-common>=0.6.0-incubating<0.7.1-incubating
0.7.1-incubating
Event History
Aug 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
May 17, 2022
Advisory Published
01:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-3153?
CVE-2017-3153 is classified as a medium severity vulnerability due to its potential impact on the affected applications.
2
How do I fix CVE-2017-3153?
To fix CVE-2017-3153, you should upgrade Apache Atlas to version 0.7.1-incubating or later.
3
Which versions of Apache Atlas are affected by CVE-2017-3153?
CVE-2017-3153 affects Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating.
4
What type of vulnerability is CVE-2017-3153?
CVE-2017-3153 is a Reflected Cross-Site Scripting (XSS) vulnerability.
5
How can CVE-2017-3153 be exploited?
CVE-2017-3153 can be exploited through maliciously crafted search queries leading to the execution of arbitrary script code in the user's browser.