CVE-2024-46910: Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Published Feb 12, 2025
·Updated
An authenticated user can perform XSS and potentially impersonate another user.
This issue affects Apache Atlas versions 2.3.0 and earlier.
Users are recommended to upgrade to version 2.4.0, which fixes the issue.
Affected Software
3 affected componentsFixes available
Apache Atlas
maven/org.apache.atlas:apache-atlas>=2.0.0<2.4.0
2.4.0
Apache Atlas>=2.0.0<2.4.0
Event History
Feb 13, 2025
CVE Published
via MITRE·08:52 AM
Data Sourced
via MITRE·08:52 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-46910?
CVE-2024-46910 is considered a high severity vulnerability due to its potential for XSS attacks and user impersonation.
2
How do I fix CVE-2024-46910?
To mitigate CVE-2024-46910, upgrade Apache Atlas to version 2.4.0 or later.
3
Who is affected by CVE-2024-46910?
CVE-2024-46910 affects all authenticated users of Apache Atlas versions 2.3.0 and earlier.
4
What type of vulnerability is CVE-2024-46910?
CVE-2024-46910 is a cross-site scripting (XSS) vulnerability.
5
Can an unauthenticated user exploit CVE-2024-46910?
No, CVE-2024-46910 requires an authenticated user to be exploited.