atlasGHSA-v62j-fcxq-j239
Stored XSS in Apache Atlas
Medium6.1CVE-2019-10070 · Published Jan 8, 2020 · updated Nov 8, 2023
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.atlas:apache-atlas Maven | < 0.8.4 | 0.8.4 |
| >= 1.0.0, < 1.2.0 | 1.2.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2019-10070
More atlas advisories
All atlas| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 102022 | Cross-site scripting in Apache Atlas | Medium6.1 | 2.1.0 |
| Aug 292017 | Apache Atlas versions 0.6.0 | High7.5 | No fix yet |
| Aug 292017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies | Medium6.1 | No fix yet |
| Aug 292017 | atlas: cross-site scripting | Medium6.1 | No fix yet |
| Aug 292017 | atlas: cross-site scripting | Medium6.1 | No fix yet |
| Aug 292017 | atlas: cross-site scripting | Medium6.1 | No fix yet |