Apache / Atlas
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-50622 | Apache Atlas: Missing Authorization on Admin Endpoints | HIGH | 8.8 | Jul 29, 2026 |
| CVE-2025-62198 | Apache Atlas: Stored XSS in Create Entity page | MEDIUM | 5.4 | Jun 22, 2026 |
| CVE-2026-40563 | Apache Atlas: Script injection allows access to unintended data | HIGH | 8.1 | May 4, 2026 |
| CVE-2024-46910 | Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user | MEDIUM | 5.3 | Feb 13, 2025 |
| CVE-2022-34271 | Apache Atlas: zip path traversal in import functionality | HIGH | 8.8 | Dec 14, 2022 |
| CVE-2020-17521 | groovy: OS temporary directory leads to information disclosure | MEDIUM | 5.5 | Dec 7, 2020 |
| CVE-2020-13928 | Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it trig… | MEDIUM | 6.1 | Sep 16, 2020 |
| CVE-2019-10070 | Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality | MEDIUM | 6.1 | Nov 18, 2019 |
| CVE-2017-3155 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting. | MEDIUM | 5.3 | Aug 29, 2017 |
| CVE-2017-3154 | Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information. | HIGH | 8.7 | Aug 29, 2017 |
| CVE-2017-3153 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality. | MEDIUM | 6.1 | Aug 29, 2017 |
| CVE-2017-3152 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality. | MEDIUM | 5.1 | Aug 29, 2017 |
| CVE-2017-3151 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. | MEDIUM | 5.3 | Aug 29, 2017 |
| CVE-2017-3150 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script. | MEDIUM | 5.3 | Aug 29, 2017 |
| CVE-2016-8752 | Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js… | HIGH | 7.5 | Aug 29, 2017 |
Showing 1 to 15 of 15 CVEs