VendorsApacheatlasall versions
Vulnerabilities

Apache Software Foundation Atlas

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2022-34271
Apache Atlas: zip path traversal in import functionality
Published 2022-12-14 · Modified
8.8EPSS 0.014
CVE-2026-50622
Apache Atlas: Missing Authorization on Admin Endpoints
Published 2026-07-29 · Analyzed
8.8EPSS 0.006
CVE-2026-40563
Apache Atlas: Script injection allows access to unintended data
Published 2026-05-04 · Modified
8.1EPSS 0.006
CVE-2016-8752
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
Published 2017-08-29 · Modified
7.5EPSS 0.021
CVE-2017-3154
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
Published 2017-08-29 · Modified
7.5EPSS 0.021
CVE-2024-46910
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Published 2025-02-13 · Analyzed
7.1EPSS 0.006
CVE-2020-13928
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.
Published 2020-09-16 · Modified
6.1EPSS 0.026
CVE-2017-3152
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
Published 2017-08-29 · Modified
6.1EPSS 0.022
CVE-2017-3153
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
Published 2017-08-29 · Modified
6.1EPSS 0.022
CVE-2017-3150
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.
Published 2017-08-29 · Modified
6.1EPSS 0.022
CVE-2017-3151
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.
Published 2017-08-29 · Modified
6.1EPSS 0.022
CVE-2017-3155
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
Published 2017-08-29 · Modified
6.1EPSS 0.021
CVE-2019-10070
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
Published 2019-11-18 · Modified
6.1EPSS 0.018
CVE-2020-17521
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Published 2020-12-07 · Modified
5.5EPSS 0.010
CVE-2025-62198
Apache Atlas: Stored XSS in Create Entity page
Published 2026-06-22 · Analyzed
5.4EPSS 0.005