First published: Tue Aug 29 2017(Updated: )
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Atlas | =0.6.0 | |
Apache Atlas | =0.6.0-rc1 | |
Apache Atlas | =0.6.0-rc2 | |
Apache Atlas | =0.7.0 | |
Apache Atlas | =0.7.0-rc1 | |
Apache Atlas | =0.7.0-rc2 | |
maven/org.apache.atlas:atlas-common | >=0.6.0-incubating<0.7.1-incubating | 0.7.1-incubating |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3155 is classified as a medium severity vulnerability due to its potential for cross frame scripting attacks.
To mitigate CVE-2017-3155, upgrade to Apache Atlas version 0.7.1-incubating or later.
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating, including their release candidates, are affected by CVE-2017-3155.
CVE-2017-3155 is a cross frame scripting vulnerability that allows attackers to execute unauthorized scripts in a user's browser.
While there are no publicly disclosed exploits specifically targeting CVE-2017-3155, the nature of cross frame scripting suggests potential for exploitation.