Skip to content
atlasGHSA-x3v6-f5fr-4wwv

Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user

Medium7.1CVE-2024-46910 · Published Feb 13, 2025

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.atlas:apache-atlas
Maven
>= 2.0.0, < 2.4.02.4.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-80
Also known as
CVE-2024-46910

More atlas advisories

All atlas
Advisory
Apache Atlas has a Code Injection Vulnerability
High7.1May 4
Apache Atlas: zip path traversal in import functionality
High8.8Dec 14, 2022
Cross-site scripting in Apache Atlas
Medium6.1Feb 10, 2022
Stored XSS in Apache Atlas
Medium6.1Jan 8, 2020
Apache Atlas versions 0.6.0
High7.5Aug 29, 2017
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies
Medium6.1Aug 29, 2017

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.