An authenticated user can perform XSS and potentially impersonate another user.
This issue affects Apache Atlas versions 2.3.0 and earlier.
Users are recommended to upgrade to version 2.4.0, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/sqzp34l4cdk21zoq5g31qlsvr7jvb1fy | Issue Tracking Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/02/12/2 | Mailing List Third Party Advisory |
Configurations
History
17 Jun 2026, 07:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.apache.org/thread/sqzp34l4cdk21zoq5g31qlsvr7jvb1fy - Issue Tracking, Mailing List, Vendor Advisory |
14 Jul 2025, 12:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () https://lists.apache.org/thread/sqzp34l4cdk21zoq5g31qlsvr7jvb1fy - Mailing List, Vendor Advisory, Issue Tracking | |
| References | () http://www.openwall.com/lists/oss-security/2025/02/12/2 - Mailing List, Third Party Advisory | |
| First Time |
Apache atlas
Apache |
13 Feb 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
13 Feb 2025, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-13 09:15
Updated : 2026-06-17 07:56
NVD link : CVE-2024-46910
Mitre link : CVE-2024-46910
CVE.ORG link : CVE-2024-46910
JSON object : View
Products Affected
apache
- atlas
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
