{"id":"CVE-2016-8752","details":"Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.","aliases":["GHSA-m2rr-h6g4-9cm9","PYSEC-2017-105"],"modified":"2026-07-08T05:48:29.727106349Z","published":"2017-08-29T20:29:00.437Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"apache:atlas","cpes":["cpe:2.3:a:apache:atlas:0.6.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.6.0:rc1:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.6.0:rc2:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.7.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.7.0:rc1:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.7.0:rc2:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.7.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.7.1:rc1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.6.0"},{"last_affected":"0.6.0"},{"introduced":"0.6.0-rc1"},{"last_affected":"0.6.0-rc1"},{"introduced":"0.6.0-rc2"},{"last_affected":"0.6.0-rc2"},{"introduced":"0.7.0"},{"last_affected":"0.7.0"},{"introduced":"0.7.0-rc1"},{"last_affected":"0.7.0-rc1"},{"introduced":"0.7.0-rc2"},{"last_affected":"0.7.0-rc2"},{"introduced":"0.7.1"},{"last_affected":"0.7.1"},{"introduced":"0.7.1-rc1"},{"last_affected":"0.7.1-rc1"}]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/f7435d66b840daa2a38ad1329d639b70f5a9476e7580ae885d422e86%40%3Cdev.atlas.apache.org%3E"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/atlas","events":[{"introduced":"8f3eb0c29e99db7b59dbd85054333f796bc1edfa"},{"last_affected":"e48bd3558a81e0d4c104f315e623ed0f6200d169"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:apache:atlas:0.7.1:rc2:*:*:*:*:*:*","cpe:2.3:a:apache:atlas:0.7.1:rc3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.7.1-rc2"},{"last_affected":"0.7.1-rc2"},{"introduced":"0.7.1-rc3"},{"last_affected":"0.7.1-rc3"}]}}],"versions":["0.7.1-rc2","0.7.1-rc3","release-0.7.1-rc3","release-0.7.1-rc2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8752.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}