CVE-2025-62198

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/nv893lhz3ok08f25j3v4z1to5nrpdp7k Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/06/20/1 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:*

History

23 Jun 2026, 14:53

Type Values Removed Values Added
First Time Apache
Apache atlas
References () https://lists.apache.org/thread/nv893lhz3ok08f25j3v4z1to5nrpdp7k - () https://lists.apache.org/thread/nv893lhz3ok08f25j3v4z1to5nrpdp7k - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/06/20/1 - () http://www.openwall.com/lists/oss-security/2026/06/20/1 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:*

22 Jun 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

22 Jun 2026, 10:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/20/1 -

22 Jun 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 08:16

Updated : 2026-06-23 14:53


NVD link : CVE-2025-62198

Mitre link : CVE-2025-62198

CVE.ORG link : CVE-2025-62198


JSON object : View

Products Affected

apache

  • atlas
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)