{"id":"GHSA-m2rr-h6g4-9cm9","summary":"Path Traversal in Apache Atlas","details":"Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.","aliases":["CVE-2016-8752","PYSEC-2017-105"],"modified":"2024-02-16T08:02:14.267284Z","published":"2022-05-17T01:18:35Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-11-04T18:45:29Z","nvd_published_at":"2017-08-29T20:29:00Z","cwe_ids":["CWE-22","CWE-284"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8752"},{"type":"PACKAGE","url":"https://github.com/apache/atlas"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/apache-atlas/PYSEC-2017-105.yaml"},{"type":"WEB","url":"https://lists.apache.org/thread.html/f7435d66b840daa2a38ad1329d639b70f5a9476e7580ae885d422e86%40%3Cdev.atlas.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/f7435d66b840daa2a38ad1329d639b70f5a9476e7580ae885d422e86@%3Cdev.atlas.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.atlas:atlas-common","ecosystem":"Maven","purl":"pkg:maven/org.apache.atlas/atlas-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.6.0-incubating"},{"fixed":"0.8-incubating"}]}],"versions":["0.6-incubating","0.7-incubating","0.7.1-incubating"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-m2rr-h6g4-9cm9/GHSA-m2rr-h6g4-9cm9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}