Skip to main content

Vendor/product archive

apache / atlas CVEs

Beta · best-effort

14 CVEs tagged to apache / atlas0 Critical, 5 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2025-62198

Published Jun 22, 2026

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-40563

Published May 4, 2026

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query st…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-46910

Published Feb 13, 2025

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34271

Published Dec 14, 2022

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13928

Published Sep 16, 2020

Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnera…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10070

Published Nov 18, 2019

Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3155

Published Aug 29, 2017

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3154

Published Aug 29, 2017

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3153

Published Aug 29, 2017

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3152

Published Aug 29, 2017

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3151

Published Aug 29, 2017

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3150

Published Aug 29, 2017

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8752

Published Aug 29, 2017

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1