atlasGHSA-x3v6-f5fr-4wwv
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Medium7.1CVE-2024-46910 · Published Feb 13, 2025
An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.atlas:apache-atlas Maven | >= 2.0.0, < 2.4.0 | 2.4.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-80
- Also known as
- CVE-2024-46910
More atlas advisories
All atlas| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 4 | Apache Atlas has a Code Injection Vulnerability | High7.1 | 2.5.0 |
| Dec 142022 | Apache Atlas: zip path traversal in import functionality | High8.8 | 2.3.0 |
| Feb 102022 | Cross-site scripting in Apache Atlas | Medium6.1 | 2.1.0 |
| Jan 82020 | Stored XSS in Apache Atlas | Medium6.1 | 0.8.4+1 more |
| Aug 292017 | Apache Atlas versions 0.6.0 | High7.5 | No fix yet |
| Aug 292017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies | Medium6.1 | No fix yet |