Cross-Site Scripting Vulnerability in Apache Atlas by Apache
CVE-2025-62198

5.4MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
22 June 2026

What is CVE-2025-62198?

An authenticated user can exploit a Cross-Site Scripting vulnerability in Apache Atlas, allowing them to execute arbitrary JavaScript code in the context of other users. This issue specifically impacts versions up to 2.4.0. It is crucial for users to update to version 2.5.0 to mitigate this risk and enhance the overall security of the application. Organizations should take immediate action to protect their data and users from potential attacks enabled by this vulnerability.

Affected Version(s)

Apache Atlas 0 <= 2.4.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Grzegorz Misiun
.