{"id":"CVE-2016-8752","description":"Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.","cvssScore":7.5,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssMetrics":[{"version":"3.0","score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-284","CWE-22"],"resolved":"MITIGATED-BY-RASP","published":"2017-08-29","lastModified":"2026-06-17","affectedProducts":[{"vendor":"apache","product":"atlas","version":"0.6.0"},{"vendor":"apache","product":"atlas","version":"0.6.0","update":"rc1"},{"vendor":"apache","product":"atlas","version":"0.6.0","update":"rc2"},{"vendor":"apache","product":"atlas","version":"0.7.0"},{"vendor":"apache","product":"atlas","version":"0.7.0","update":"rc1"},{"vendor":"apache","product":"atlas","version":"0.7.0","update":"rc2"},{"vendor":"apache","product":"atlas","version":"0.7.1"},{"vendor":"apache","product":"atlas","version":"0.7.1","update":"rc1"},{"vendor":"apache","product":"atlas","version":"0.7.1","update":"rc2"},{"vendor":"apache","product":"atlas","version":"0.7.1","update":"rc3"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/apache/atlas","source":"osv","tags":["PACKAGE"]},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/apache-atlas/PYSEC-2017-105.yaml","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/f7435d66b840daa2a38ad1329d639b70f5a9476e7580ae885d422e86%40%3Cdev.atlas.apache.org%3E","source":"osv","tags":["WEB"]},{"url":"https://lists.apache.org/thread.html/f7435d66b840daa2a38ad1329d639b70f5a9476e7580ae885d422e86@%3Cdev.atlas.apache.org%3E","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.atlas:atlas-common"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.atlas:atlas-common). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"CWE-22 (Path Traversal) is mitigable by an ARMR path-traversal security rule.","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"affectedProducts":[{"vendor":"apache","product":"atlas","isKnown":false,"cpe":"cpe:2.3:a:apache:atlas:0.6.0:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.apache.atlas:atlas-common","introduced":"0.6.0-incubating","fixed":"0.8-incubating"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.02127,"percentile":0.80902},"ssvc":{"available":false}}