Skip to content
atlasGHSA-p782-4j23-xqcg

Apache Atlas: zip path traversal in import functionality

High8.8CVE-2022-34271 · Published Dec 14, 2022 · updated Nov 8, 2023

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.atlas:apache-atlas
Maven
>= 0.8.4, < 2.3.02.3.0
Details and references

More atlas advisories

All atlas
Advisory
Apache Atlas has a Code Injection Vulnerability
High7.1May 4
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Medium7.1Feb 13, 2025
Cross-site scripting in Apache Atlas
Medium6.1Feb 10, 2022
Stored XSS in Apache Atlas
Medium6.1Jan 8, 2020
Apache Atlas versions 0.6.0
High7.5Aug 29, 2017
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies
Medium6.1Aug 29, 2017

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.