Skip to content
atlasGHSA-h6xq-3h62-99qx

Cross-site scripting in Apache Atlas

Medium6.1CVE-2020-13928 · Published Feb 10, 2022 · updated Nov 8, 2023

Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.atlas:apache-atlas
Maven
< 2.1.02.1.0
Details and references

More atlas advisories

All atlas
Advisory
Apache Atlas has a Code Injection Vulnerability
High7.1May 4
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Medium7.1Feb 13, 2025
Apache Atlas: zip path traversal in import functionality
High8.8Dec 14, 2022
Stored XSS in Apache Atlas
Medium6.1Jan 8, 2020
Apache Atlas versions 0.6.0
High7.5Aug 29, 2017
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies
Medium6.1Aug 29, 2017

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.