CVE-2016-8752
published 2017-08-29CVE-2016-8752: Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.13%
79.9th percentile
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | atlas | — | — |
| apache | atlas | — | — |
| apache | atlas | — | — |
| apache_software_foundation | apache_atlas | — | — |
| apache_software_foundation | apache_atlas | — | — |
| apache_software_foundation | apache_atlas | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Path Traversal in Apache Atlas
osv·2022-05-17
CVE-2016-8752 [HIGH] Path Traversal in Apache Atlas
Path Traversal in Apache Atlas
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
GHSA
Path Traversal in Apache Atlas
ghsa·2022-05-17
CVE-2016-8752 [HIGH] CWE-22 Path Traversal in Apache Atlas
Path Traversal in Apache Atlas
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
OSV
CVE-2016-8752: Apache Atlas versions 0
osv·2017-08-29
CVE-2016-8752 CVE-2016-8752: Apache Atlas versions 0
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-29
Published