Skip to content
atlasGHSA-v62j-fcxq-j239

Stored XSS in Apache Atlas

Medium6.1CVE-2019-10070 · Published Jan 8, 2020 · updated Nov 8, 2023

Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.atlas:apache-atlas
Maven
< 0.8.40.8.4
>= 1.0.0, < 1.2.01.2.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2019-10070

More atlas advisories

All atlas
Advisory
Cross-site scripting in Apache Atlas
Medium6.1Feb 10, 2022
Apache Atlas versions 0.6.0
High7.5Aug 29, 2017
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies
Medium6.1Aug 29, 2017
atlas: cross-site scripting
Medium6.1Aug 29, 2017
atlas: cross-site scripting
Medium6.1Aug 29, 2017
atlas: cross-site scripting
Medium6.1Aug 29, 2017

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.