oss-sec mailing list archives

CVE-2024-46910: Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user


From: Madhan Neethiraj <madhan () apache org>
Date: Wed, 12 Feb 2025 19:02:31 +0000

Severity: important

Affected versions:

- Apache Atlas 2.0.0 through 2.3.0

Description:

An authenticated user can perform XSS and potentially impersonate another user.

This issue affects Apache Atlas versions 2.3.0 and earlier.

Users are recommended to upgrade to version 2.4.0, which fixes the issue.

Credit:

basavaraj () seciqtech com (finder)

References:

https://atlas.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-46910


Current thread: