CVE-2017-3152
published 2017-08-29CVE-2017-3152: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
2.21%
80.7th percentile
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | atlas | — | — |
| apache | atlas | — | — |
| apache_software_foundation | apache_atlas | — | — |
| apache_software_foundation | apache_atlas | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross-site Scripting in Apache Atlas
ghsa·2022-05-17
CVE-2017-3152 [MEDIUM] CWE-79 Cross-site Scripting in Apache Atlas
Cross-site Scripting in Apache Atlas
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
OSV
Cross-site Scripting in Apache Atlas
osv·2022-05-17
CVE-2017-3152 [MEDIUM] Cross-site Scripting in Apache Atlas
Cross-site Scripting in Apache Atlas
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
OSV
CVE-2017-3152: Apache Atlas versions 0
osv·2017-08-29
CVE-2017-3152 CVE-2017-3152: Apache Atlas versions 0
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
Red Hat
perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
vendor_redhat·2017-07-01·CVSS 5.9
CVE-2017-10789 [MEDIUM] CWE-300 perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
perl-DBD-MySQL: Possible MITM attack when mysql_ssl=1
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: perl-DBD-MySQL (Red Hat Enterprise Linux 5) - Will not fix
Package: perl-DBD-MySQL (Red Hat E
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100577https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2a0520acde71ddefee0ea%40%3Cdev.atlas.apache.org%3Ehttp://www.securityfocus.com/bid/100577https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2a0520acde71ddefee0ea%40%3Cdev.atlas.apache.org%3E
2017-08-29
Published