{"id":"GHSA-v73p-f52r-fmmr","summary":"Apache Atlas UI: Authenticated User XSS","details":"An authenticated user can perform XSS.\n\nThis issue affects Apache Atlas versions 2.4.0 and earlier.\n\nUsers are recommended to upgrade to version 2.5.0, which fixes the issue.","aliases":["CVE-2025-62198"],"modified":"2026-09-11T22:15:04.037824137Z","published":"2026-06-22T09:30:45Z","database_specific":{"cwe_ids":["CWE-80"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-11T22:05:26Z","nvd_published_at":"2026-06-22T08:16:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62198"},{"type":"WEB","url":"https://github.com/apache/atlas/commit/800f979307d6ea0f0b6563ec890f6b728022e497"},{"type":"PACKAGE","url":"https://github.com/apache/atlas"},{"type":"WEB","url":"https://lists.apache.org/thread/nv893lhz3ok08f25j3v4z1to5nrpdp7k"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/20/1"}],"affected":[{"package":{"name":"org.apache.atlas:atlas-dashboardv2","ecosystem":"Maven","purl":"pkg:maven/org.apache.atlas/atlas-dashboardv2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.0"}]}],"versions":["0.7-incubating","0.7.1-incubating","0.8-incubating","0.8.1","0.8.2","0.8.3","0.8.4","1.0.0","1.0.0-alpha","1.1.0","1.2.0","2.0.0","2.1.0","2.2.0","2.3.0","2.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v73p-f52r-fmmr/GHSA-v73p-f52r-fmmr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}