CVE-2024-46910 - CVE House
Back to Database
Status published Unknown CVE-2024-46910

Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user

Vulnerability Description

An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-46910

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • SecIQ Technologies LLP
  • Darpan Patel (SecIQ Technologies)

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Atlas
Vulnerable Versions:
2.0.0

Timeline

Official Publish: February 13th, 2025
Last Modified: October 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)