{"id":"GHSA-v62j-fcxq-j239","summary":"Stored XSS in Apache Atlas","details":"Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality","aliases":["CVE-2019-10070"],"modified":"2023-11-08T04:00:39.434638Z","published":"2020-01-08T17:26:53Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-01-08T17:26:02Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10070"},{"type":"WEB","url":"https://lists.apache.org/thread.html/cc21437c4c5053a13e13332d614d5172f39da03491fe17ae260be221@%3Cdev.atlas.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.atlas:apache-atlas","ecosystem":"Maven","purl":"pkg:maven/org.apache.atlas/apache-atlas"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.4"}]}],"versions":["0.5-incubating","0.6-incubating","0.7-incubating","0.7.1-incubating","0.8-incubating","0.8.1","0.8.2","0.8.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-v62j-fcxq-j239/GHSA-v62j-fcxq-j239.json"}},{"package":{"name":"org.apache.atlas:apache-atlas","ecosystem":"Maven","purl":"pkg:maven/org.apache.atlas/apache-atlas"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.0"}]}],"versions":["1.0.0","1.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-v62j-fcxq-j239/GHSA-v62j-fcxq-j239.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}