CVE-2025-62198: Apache Atlas: Stored XSS in Create Entity page
Published Jun 20, 2026
·Updated
An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are recommended to upgrade to version 2.5.0, which fixes the issue.
Affected Software
2 affected components
Apache Atlas<=2.4.0
Apache Atlas<2.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Atlasto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Jun 22, 2026
CVE Published
via MITRE·07:47 AM
Data Sourced
via MITRE·07:47 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62198?
The severity of CVE-2025-62198 is rated as medium with a CVSS score of 5.4.
2
How do I fix CVE-2025-62198?
To fix CVE-2025-62198, upgrade to Apache Atlas version 2.5.0 or later.
3
What is the impact of CVE-2025-62198?
CVE-2025-62198 allows an authenticated user to perform stored Cross-Site Scripting (XSS) attacks.
4
Which versions of Apache Atlas are affected by CVE-2025-62198?
CVE-2025-62198 affects Apache Atlas versions 2.4.0 and earlier.
5
What type of vulnerability is CVE-2025-62198?
CVE-2025-62198 is categorized as a stored Cross-Site Scripting (XSS) vulnerability.