← Vulnerability feed

Vulnerability record · CVE-2017-3150 · published 29 August 2017

CVE-2017-3150: Apache atlas cross-site scripting vulnerability

Apache · Atlas

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

6.1 CVSS 3.0 Medium EPSS 2.2% · top 18.1% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-50622Apache atlas missing authorization vulnerabilityDescription: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated …EPSS 0.58%8.8CVE-2022-34271Apache atlas path traversal vulnerabilityA vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas vers…EPSS 1.4%8.1CVE-2026-40563Apache atlas code injection vulnerabilityDescription: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that …EPSS 0.60%7.5CVE-2016-8752Apache atlas improper access control vulnerabilityApache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI…EPSS 2.1%7.5CVE-2017-3154Apache atlas information exposure vulnerabilityError responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.EPSS 2.1%7.1CVE-2024-46910Apache atlas vulnerabilityAn authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are…EPSS 0.57%6.1CVE-2020-13928Apache atlas cross-site scripting vulnerabilityApache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of th…EPSS 2.6%6.1CVE-2019-10070Apache atlas cross-site scripting vulnerabilityApache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionalityEPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2017-3150), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.