PT-2026-51187 · Apache · Apache Atlas
Grzegorz Misiun
·
Published
2026-06-20
·
Updated
2026-06-22
·
CVE-2025-62198
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Atlas versions 2.4.0 and earlier
Description
An authenticated user can perform stored Cross-Site Scripting (XSS), which is a technique where malicious scripts are permanently stored on the target server, on the Create Entity page.
Recommendations
Upgrade to version 2.5.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Atlas