{"id":"CVE-2022-34271","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-34271","summary":"Apache Atlas: zip path traversal in import functionality","details":"A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.","published":"2022-12-14T09:30:24Z","modified":"2023-11-08T04:09:45.334674Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.atlas:apache-atlas","fixedVersion":"2.3.0"}],"fix":{"url":"https://github.com/apache/atlas/commit/3415913d252597c24c6b5d19d315375a49e64152","label":"apache/atlas@3415913"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34271"},{"type":"WEB","url":"https://github.com/apache/atlas/commit/3415913d252597c24c6b5d19d315375a49e64152"},{"type":"PACKAGE","url":"https://github.com/apache/atlas"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/ATLAS-4622"},{"type":"WEB","url":"https://lists.apache.org/thread/0rqvcxo6brmos9w3lzfsdn2lsmlblpw3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:09:45.334674Z"}}