atlasGHSA-p782-4j23-xqcg
Apache Atlas: zip path traversal in import functionality
High8.8CVE-2022-34271 · Published Dec 14, 2022 · updated Nov 8, 2023
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.atlas:apache-atlas Maven | >= 0.8.4, < 2.3.0 | 2.3.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2022-34271
More atlas advisories
All atlas| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 4 | Apache Atlas has a Code Injection Vulnerability | High7.1 | 2.5.0 |
| Feb 132025 | Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user | Medium7.1 | 2.4.0 |
| Feb 102022 | Cross-site scripting in Apache Atlas | Medium6.1 | 2.1.0 |
| Jan 82020 | Stored XSS in Apache Atlas | Medium6.1 | 0.8.4+1 more |
| Aug 292017 | Apache Atlas versions 0.6.0 | High7.5 | No fix yet |
| Aug 292017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies | Medium6.1 | No fix yet |