CVE-2022-34271
published 2022-12-14CVE-2022-34271: A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from…
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.38%
69.3th percentile
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | atlas | 0.8.4 – 2.2.0 | — |
| apache_software_foundation | apache_atlas | >= 0.8.4 < 2.3.0 | 2.3.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Atlas: zip path traversal in import functionality
osv·2022-12-14
CVE-2022-34271 [HIGH] Apache Atlas: zip path traversal in import functionality
Apache Atlas: zip path traversal in import functionality
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
GHSA
Apache Atlas: zip path traversal in import functionality
ghsa·2022-12-14
CVE-2022-34271 [HIGH] CWE-22 Apache Atlas: zip path traversal in import functionality
Apache Atlas: zip path traversal in import functionality
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-14
Published