atlasGHSA-h6xq-3h62-99qx
Cross-site scripting in Apache Atlas
Medium6.1CVE-2020-13928 · Published Feb 10, 2022 · updated Nov 8, 2023
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.atlas:apache-atlas Maven | < 2.1.0 | 2.1.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2020-13928
More atlas advisories
All atlas| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 4 | Apache Atlas has a Code Injection Vulnerability | High7.1 | 2.5.0 |
| Feb 132025 | Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user | Medium7.1 | 2.4.0 |
| Dec 142022 | Apache Atlas: zip path traversal in import functionality | High8.8 | 2.3.0 |
| Jan 82020 | Stored XSS in Apache Atlas | Medium6.1 | 0.8.4+1 more |
| Aug 292017 | Apache Atlas versions 0.6.0 | High7.5 | No fix yet |
| Aug 292017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies | Medium6.1 | No fix yet |