XSS Vulnerability in Apache Atlas Affecting Versions Prior to 2.1.0
CVE-2020-13928
6.1MEDIUM
Summary
Apache Atlas before version 2.1.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability that arises due to improper sanitization of user inputs while saving searches and rendering element values. This flaw could allow attackers to inject malicious scripts into the web application, potentially leading to unauthorized access to sensitive information or manipulation of user sessions. It is essential for users of affected versions to apply the necessary patches and updates to mitigate this security risk.
Affected Version(s)
Apache Atlas Apache Atlas 2.0.1
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved