CVE-2022-34271: Apache Atlas: zip path traversal in import functionality
Published Dec 14, 2022
·Updated
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
Affected Software
1 affected component
Apache Atlas>=0.8.4<=2.2.0
Event History
Dec 14, 2022
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-34271?
CVE-2022-34271 has been assigned a medium severity rating due to its impact on Apache Atlas installations.
2
How do I fix CVE-2022-34271?
To fix CVE-2022-34271, upgrade Apache Atlas to version 2.2.1 or later.
3
What versions of Apache Atlas are affected by CVE-2022-34271?
CVE-2022-34271 affects Apache Atlas versions from 0.8.4 to 2.2.0.
4
What is the impact of CVE-2022-34271?
CVE-2022-34271 allows an authenticated user to write to the web server's filesystem, which could lead to further exploitation.
5
Who can exploit CVE-2022-34271?
Only authenticated users of Apache Atlas can exploit CVE-2022-34271 due to the access restrictions.