All 13 CVE vulnerabilities found in Apache Atlas, with AI-generated Chinese analysis, references, and POCs.
This page documents known vulnerabilities affecting Apache Atlas, a metadata management and governance platform. It aggregates security weaknesses categorized under various Common Weakness Enumeration (CWE) classifications, providing a centralized view of the product's security posture. The collection includes reported issues spanning from the initial public release of the software up to the most recent disclosures, ensuring a comprehensive historical record. By consolidating data from multiple sources, this resource offers a clear timeline of when specific flaws were identified and addressed. Users can track vendor advisories to stay informed about critical patches and configuration changes. The page also allows for an in-depth understanding of specific weakness classes, illustrating how common attack vectors manifest in Apache Atlas environments. Additionally, it serves as a lookup tool for examining the vulnerability history of the product, helping security teams assess long-term risk trends and remediation effectiveness. This approach supports both proactive monitoring and retrospective analysis for administrators and security researchers. The information is presented without promotional language, focusing strictly on factual data to aid in decision-making. Readers will find a structured overview that highlights the evolution of security issues within the metadata management layer. This context is essential for organizations relying on Atlas for data governance, as it clarifies which versions require immediate attention. The aggregated view simplifies the complexity of disparate security bulletins into a single, accessible reference point for continuous improvement.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50622 | Apache Atlas: Missing Authorization on Admin Endpoints CWE-862 | - | - | 2026-07-29 |
| CVE-2025-62198 | Apache Atlas: Stored XSS in Create Entity page CWE-80 | - | - | 2026-06-22 |
| CVE-2026-40563 | Apache Atlas: Script injection allows access to unintended data CWE-94 | 9.8 | - | 2026-05-04 |
| CVE-2024-46910 | Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user CWE-80 | 5.4 | - | 2025-02-13 |
| CVE-2022-34271 | Apache Atlas: zip path traversal in import functionality CWE-22 | 8.1 | - | 2022-12-14 |
| CVE-2020-13928 | Apache Atlas 跨站脚本漏洞 | 6.1 | - | 2020-09-16 |
| CVE-2016-8752 | Apache Atlas 信息泄露漏洞 | 5.3 | - | 2017-08-29 |
| CVE-2017-3150 | Apache 跨站脚本漏洞 | 5.4 | - | 2017-08-29 |
| CVE-2017-3151 | Apache Atlas 跨站脚本漏洞 | 5.4 | - | 2017-08-29 |
| CVE-2017-3152 | Apache Atlas 安全漏洞 | 6.1 | - | 2017-08-29 |
| CVE-2017-3153 | Apache Atlas 跨站脚本漏洞 | 6.1 | - | 2017-08-29 |
| CVE-2017-3154 | Apache Atlas 安全漏洞 | 7.5 | - | 2017-08-29 |
| CVE-2017-3155 | Apache Atlas 跨站脚本漏洞 | 6.1 | - | 2017-08-29 |
All 13 known CVE vulnerabilities affecting Apache Atlas with full Chinese analysis, references, and POCs where available.