CVE-2022-34271

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
References
Link Resource
https://lists.apache.org/thread/0rqvcxo6brmos9w3lzfsdn2lsmlblpw3 Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:48

Type Values Removed Values Added
Summary A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

16 Dec 2022, 17:35

Type Values Removed Values Added
CPE cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:*
First Time Apache
Apache atlas
References (MISC) https://lists.apache.org/thread/0rqvcxo6brmos9w3lzfsdn2lsmlblpw3 - (MISC) https://lists.apache.org/thread/0rqvcxo6brmos9w3lzfsdn2lsmlblpw3 - Mailing List, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-20 CWE-22

14 Dec 2022, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-14 09:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-34271

Mitre link : CVE-2022-34271

CVE.ORG link : CVE-2022-34271


JSON object : View

Products Affected

apache

  • atlas
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')