#VU70445 Path traversal in Apache Atlas - CVE-2022-34271
Published: December 20, 2022
Apache Atlas
Apache Foundation
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences inside .zip files within the import functionality. A remote user can upload a specially crafted .zip file and write files to arbitrary locations on the web server.