CVE-2017-3154: Infoleak
Published Aug 29, 2017
·Updated
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
Affected Software
7 affected componentsFixes available
Apache Atlas=0.6.0
Apache Atlas=0.6.0-rc1
Apache Atlas=0.6.0-rc2
Apache Atlas=0.7.0
Apache Atlas=0.7.0-rc1
Apache Atlas=0.7.0-rc2
maven/org.apache.atlas:atlas-common>=0.6.0-incubating<0.7.1-incubating
0.7.1-incubating
Event History
Aug 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
May 17, 2022
Advisory Published
via GitHub·01:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-3154?
CVE-2017-3154 is considered a medium severity vulnerability due to the exposure of sensitive information in error responses.
2
How do I fix CVE-2017-3154?
To fix CVE-2017-3154, upgrade Apache Atlas to version 0.7.1-incubating or later.
3
Which versions of Apache Atlas are affected by CVE-2017-3154?
CVE-2017-3154 affects Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating.
4
What kind of information is exposed due to CVE-2017-3154?
CVE-2017-3154 may expose stack traces and excessive error information in the error responses.
5
Where can I find more details about CVE-2017-3154?
Details about CVE-2017-3154 can be found in the Apache Atlas project documentation and security advisory.