An authenticated user can perform XSS and potentially impersonate another user.
This issue affects Apache Atlas versions 2.3.0 and earlier.
Users are recommended to upgrade to version 2.4.0, which fixes the issue.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/sqzp34l4cdk21zoq5g31qlsvr7jvb1fy | Mailing List Vendor Advisory Issue Tracking |
http://www.openwall.com/lists/oss-security/2025/02/12/2 | Mailing List Third Party Advisory |
Configurations
History
14 Jul 2025, 12:03
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:* | |
References | () https://lists.apache.org/thread/sqzp34l4cdk21zoq5g31qlsvr7jvb1fy - Mailing List, Vendor Advisory, Issue Tracking | |
References | () http://www.openwall.com/lists/oss-security/2025/02/12/2 - Mailing List, Third Party Advisory | |
First Time |
Apache atlas
Apache |
13 Feb 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
13 Feb 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-13 09:15
Updated : 2025-07-14 12:03
NVD link : CVE-2024-46910
Mitre link : CVE-2024-46910
CVE.ORG link : CVE-2024-46910
JSON object : View
Products Affected
apache
- atlas
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)