GHSA-x3v6-f5fr-4wwv

Suggest an improvement
Source
https://github.com/advisories/GHSA-x3v6-f5fr-4wwv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-x3v6-f5fr-4wwv/GHSA-x3v6-f5fr-4wwv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x3v6-f5fr-4wwv
Aliases
Published
2025-02-13T09:31:26Z
Modified
2025-02-13T22:26:01Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Details

An authenticated user can perform XSS and potentially impersonate another user.

This issue affects Apache Atlas versions 2.3.0 and earlier.

Users are recommended to upgrade to version 2.4.0, which fixes the issue.

Database specific
{
    "cwe_ids":  [
        "CWE-80"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-02-13T17:24:09Z",
    "nvd_published_at":  "2025-02-13T09:15:09Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.apache.atlas:apache-atlas

Package

Name
org.apache.atlas:apache-atlas
View open source insights on deps.dev
Purl
pkg:maven/org.apache.atlas/apache-atlas

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.4.0

Affected versions

2.*
2.0.0
2.1.0
2.2.0
2.3.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-x3v6-f5fr-4wwv/GHSA-x3v6-f5fr-4wwv.json"