id: PYSEC-2017-107 details: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. aliases: - CVE-2017-3151 modified: '2023-12-01T23:23:55.413874Z' published: '2017-08-29T20:29:00Z' references: - type: WEB url: http://www.securityfocus.com/bid/100547 - type: ADVISORY url: http://www.securityfocus.com/bid/100547 - type: WEB url: https://lists.apache.org/thread.html/4a4fef91e067fd0d9da569e30867c1fa65e2a0520acde71ddefee0ea%40%3Cdev.atlas.apache.org%3E affected: - package: name: apache-atlas ecosystem: PyPI purl: pkg:pypi/apache-atlas ranges: - type: ECOSYSTEM events: - introduced: '0' versions: - 0.0.1 - 0.0.11 - 0.0.12 - 0.0.13 - 0.0.14 - 0.0.2 - 0.0.3 - 0.0.4 - 0.0.5 - 0.0.15 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N