Apache

Atlas

12 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Published 13.02.2025 09:15:09
  • Last modified 14.07.2025 12:03:56

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.

  • EPSS 0.31%
  • Published 14.12.2022 09:15:09
  • Last modified 21.11.2024 07:09:11

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

  • EPSS 0.36%
  • Published 07.12.2020 20:15:12
  • Last modified 21.11.2024 05:08:16

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operatin...

  • EPSS 1.89%
  • Published 16.09.2020 18:15:12
  • Last modified 21.11.2024 05:02:10

Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.

  • EPSS 1.44%
  • Published 18.11.2019 21:15:11
  • Last modified 21.11.2024 04:18:20

Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

  • EPSS 1.02%
  • Published 29.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.

  • EPSS 1.02%
  • Published 29.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

  • EPSS 1.02%
  • Published 29.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

  • EPSS 1.44%
  • Published 29.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

  • EPSS 1.44%
  • Published 29.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.