atlasPYSEC-2017-105
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
High7.5CVE-2016-8752 · Published Aug 29, 2017 · updated Oct 9, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-atlas PyPI | all versions | No fix yet |
Details and references
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the CVSS score
- Also known as
- CVE-2016-8752, GHSA-m2rr-h6g4-9cm9