CVE-2025-62198
published 2026-06-22CVE-2025-62198: An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.51%
40.3th percentile
An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are recommended to upgrade to version 2.5.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | atlas | < 2.5.0 | 2.5.0 |
| apache_software_foundation | apache_atlas | <= 2.4.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An authenticated user can perform XSS.
ghsa_unreviewed·2026-06-22
CVE-2025-62198 [MEDIUM] CWE-80 An authenticated user can perform XSS.
An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are recommended to upgrade to version 2.5.0, which fixes the issue.
VulDB
Apache Atlas up to 2.4.0 Create Entity Page cross site scripting
vuldb·2026-06-21
CVE-2025-62198 [LOW] Apache Atlas up to 2.4.0 Create Entity Page cross site scripting
A vulnerability identified as problematic has been detected in Apache Atlas up to 2.4.0. The impacted element is an unknown function of the component Create Entity Page. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2025-62198. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published