Apache
Apache Atlas: vulnerabilidades y CVE
Apache Atlas tiene 15 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-50622 | Alta (8.8) | 0.58% | — | 29 jul 2026 | Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative… |
| CVE-2025-62198 | Media (5.4) | 0.51% | — | 22 jun 2026 | An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue. |
| CVE-2026-40563 | Alta (8.1) | 0.60% | — | 4 may 2026 | Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin… |
| CVE-2024-46910 | Alta (7.1) | 0.57% | — | 13 feb 2025 | An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue. |
| CVE-2022-34271 | Alta (8.8) | 1.4% | — | 14 dic 2022 | A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. |
| CVE-2020-17521 | Media (5.5) | 1.0% | — | 7 dic 2020 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is… |
| CVE-2020-13928 | Media (6.1) | 2.6% | — | 16 sept 2020 | Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability. |
| CVE-2019-10070 | Media (6.1) | 1.8% | — | 18 nov 2019 | Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality |
| CVE-2017-3155 | Media (6.1) | 2.1% | — | 29 ago 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting. |
| CVE-2017-3154 | Alta (7.5) | 2.1% | — | 29 ago 2017 | Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information. |
| CVE-2017-3153 | Media (6.1) | 2.2% | — | 29 ago 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality. |
| CVE-2017-3152 | Media (6.1) | 2.2% | — | 29 ago 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality. |
| CVE-2017-3151 | Media (6.1) | 2.2% | — | 29 ago 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality. |
| CVE-2017-3150 | Media (6.1) | 2.2% | — | 29 ago 2017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script. |
| CVE-2016-8752 | Alta (7.5) | 2.1% | — | 29 ago 2017 | Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.