A AegiFlow
MEDIUMCVSS 5.4EPSS 0.5%

CVE-2025-62198

Apache Atlas UI: Authenticated User XSS

Published
2026-06-22
Modified
2026-09-11
EPSS percentile
42%
Aliases
GHSA-v73p-f52r-fmmr
Sources
github-advisory

Summary

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.apache.atlas:atlas-dashboardv22.5.0

Remediation: Upgrade to 2.5.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.