keanhankins / ranger

Mirror of Apache Ranger
Apache License 2.0
0 stars 0 forks source link

CVE-2022-34271 (High) detected in atlas-intg-2.1.0.jar #396

Open mend-for-github-com[bot] opened 1 year ago

mend-for-github-com[bot] commented 1 year ago

CVE-2022-34271 - High Severity Vulnerability

Vulnerable Library - atlas-intg-2.1.0.jar

Apache Atlas Integration

Library home page: https://atlas.apache.org

Path to dependency file: /ranger-atlas-plugin-shim/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/atlas/atlas-intg/2.1.0/atlas-intg-2.1.0.jar,/home/wss-scanner/.m2/repository/org/apache/atlas/atlas-intg/2.1.0/atlas-intg-2.1.0.jar,/canner/.m2/repository/org/apache/atlas/atlas-intg/2.1.0/atlas-intg-2.1.0.jar

Dependency Hierarchy: - :x: **atlas-intg-2.1.0.jar** (Vulnerable Library)

Found in base branch: master

Vulnerability Details

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

Publish Date: 2022-12-14

URL: CVE-2022-34271

CVSS 3 Score Details (8.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.cve.org/CVERecord?id=CVE-2022-34271

Release Date: 2022-12-14

Fix Resolution: 2.3.0


:rescue_worker_helmet: Automatic Remediation is available for this issue