Cross Frame Scripting Vulnerability in Apache Atlas by Apache
CVE-2017-3155

6.1MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
29 August 2017

Summary

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating are susceptible to cross frame scripting vulnerabilities. This issue allows malicious actors to exploit the application through a web browser, potentially leading to unauthorized actions on behalf of the user. It is crucial for administrators to address this vulnerability promptly to safeguard user data and maintain the integrity of applications using Apache Atlas.

Affected Version(s)

Apache Atlas 0.6.0-incubating

Apache Atlas 0.7.0-incubating

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.