Apache Atlas vulnerabilities
14 known vulnerabilities affecting apache/atlas.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2026-40563P3HIGHCVSS 8.1≥ 0.8, < 2.5.02026-05-04
CVE-2026-40563 [HIGH] CWE-94 CVE-2026-40563: Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data
Affect Version:
This issue affects Apache Atlas: from 0.8 throu
nvd
CVE-2022-34271P3HIGHCVSS 8.8≥ 0.8.4, ≤ 2.2.02022-12-14
CVE-2022-34271 [HIGH] CWE-22 CVE-2022-34271: A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
nvd
CVE-2016-8752P3HIGHCVSS 7.5v0.6.0v0.7.0+1 more2017-08-29
CVE-2016-8752 [HIGH] CWE-284 CVE-2016-8752: Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
nvd
CVE-2017-3154P3HIGHCVSS 7.5v0.6.0v0.7.02017-08-29
CVE-2017-3154 [HIGH] CWE-200 CVE-2017-3154: Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trac
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
nvd
CVE-2024-46910P3HIGHCVSS 7.1≥ 2.0.0, < 2.4.02025-02-13
CVE-2024-46910 [HIGH] CWE-80 CVE-2024-46910: An authenticated user can perform XSS and potentially impersonate another user. This issue affects
An authenticated user can perform XSS and potentially impersonate another user.
This issue affects Apache Atlas versions 2.3.0 and earlier.
Users are recommended to upgrade to version 2.4.0, which fixes the issue.
nvd
CVE-2019-10070P4MEDIUMCVSS 6.1v0.8.3v1.1.02019-11-18
CVE-2019-10070 [MEDIUM] CWE-79 CVE-2019-10070: Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the se
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
nvd
CVE-2025-62198P4MEDIUMCVSS 5.4fixed in 2.5.02026-06-22
CVE-2025-62198 [MEDIUM] CWE-80 CVE-2025-62198: An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier.
An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are recommended to upgrade to version 2.5.0, which fixes the issue.
nvd
CVE-2017-3152P4MEDIUMCVSS 6.1v0.6.0v0.7.02017-08-29
CVE-2017-3152 [MEDIUM] CWE-79 CVE-2017-3152: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.
nvd
CVE-2017-3150P4MEDIUMCVSS 6.1v0.6.0v0.7.02017-08-29
CVE-2017-3150 [MEDIUM] CWE-79 CVE-2017-3150: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.
nvd
CVE-2017-3151P4MEDIUMCVSS 6.1v0.6.0v0.7.02017-08-29
CVE-2017-3151 [MEDIUM] CWE-79 CVE-2017-3151: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Si
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.
nvd
CVE-2017-3155P4MEDIUMCVSS 6.1v0.6.0v0.7.02017-08-29
CVE-2017-3155 [MEDIUM] CWE-79 CVE-2017-3155: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scr
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.
nvd
CVE-2020-17521P4MEDIUMCVSS 5.5v2.1.02020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
CVE-2020-13928P4MEDIUMCVSS 6.1fixed in 2.1.02020-09-16
CVE-2020-13928 [MEDIUM] CWE-79 CVE-2020-13928: Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements val
Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.
nvd
CVE-2017-3153P4MEDIUMCVSS 6.1v0.6.0v0.7.02017-08-29
CVE-2017-3153 [MEDIUM] CWE-79 CVE-2017-3153: Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS i
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.
nvd