First published: Wed Feb 12 2025(Updated: )
An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Atlas | ||
maven/org.apache.atlas:apache-atlas | >=2.0.0<2.4.0 | 2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46910 is considered a high severity vulnerability due to its potential for XSS attacks and user impersonation.
To mitigate CVE-2024-46910, upgrade Apache Atlas to version 2.4.0 or later.
CVE-2024-46910 affects all authenticated users of Apache Atlas versions 2.3.0 and earlier.
CVE-2024-46910 is a cross-site scripting (XSS) vulnerability.
No, CVE-2024-46910 requires an authenticated user to be exploited.