CVE-2017-3155: XSS
Published Aug 29, 2017
·Updated
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
Affected Software
7 affected componentsFixes available
Apache Atlas=0.6.0
Apache Atlas=0.6.0-rc1
Apache Atlas=0.6.0-rc2
Apache Atlas=0.7.0
Apache Atlas=0.7.0-rc1
Apache Atlas=0.7.0-rc2
maven/org.apache.atlas:atlas-common>=0.6.0-incubating<0.7.1-incubating
0.7.1-incubating
Event History
Aug 29, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
May 17, 2022
Advisory Published
01:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-3155?
CVE-2017-3155 is classified as a medium severity vulnerability due to its potential for cross frame scripting attacks.
2
How do I fix CVE-2017-3155?
To mitigate CVE-2017-3155, upgrade to Apache Atlas version 0.7.1-incubating or later.
3
Which versions of Apache Atlas are affected by CVE-2017-3155?
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating, including their release candidates, are affected by CVE-2017-3155.
4
What type of vulnerability is CVE-2017-3155?
CVE-2017-3155 is a cross frame scripting vulnerability that allows attackers to execute unauthorized scripts in a user's browser.
5
Is there a known exploit for CVE-2017-3155?
While there are no publicly disclosed exploits specifically targeting CVE-2017-3155, the nature of cross frame scripting suggests potential for exploitation.