CVE-2019-10070: XSS
Published Nov 18, 2019
·Updated
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
Affected Software
2 affected components
Apache Atlas=0.8.3
Apache Atlas=1.1.0
Event History
Nov 18, 2019
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-10070?
CVE-2019-10070 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2019-10070?
To fix CVE-2019-10070, you should upgrade Apache Atlas to version 0.8.4 or higher, or 1.1.1 or higher.
3
What versions of Apache Atlas are affected by CVE-2019-10070?
CVE-2019-10070 affects Apache Atlas versions 0.8.3 and 1.1.0.
4
What type of vulnerability is CVE-2019-10070?
CVE-2019-10070 is a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2019-10070 lead to data breaches?
Yes, if exploited, CVE-2019-10070 can potentially lead to data breaches by executing malicious scripts in the context of a user session.