Impact
An authenticated user can inject and store malicious scripts through the Create Entity page in Apache Atlas. The stored payload is executed whenever any user subsequently loads the affected page, potentially enabling session hijacking, credential theft, or defacement. This is a classic Stored Cross‑Site Scripting flaw identified as CWE‑80.
Affected Systems
The flaw exists in Apache Atlas versions 2.4.0 and earlier, distributed by the Apache Software Foundation. Users of these releases should upgrade to 2.5.0 or later to eliminate the vulnerability.
Risk and Exploitability
Because the vulnerability requires valid authenticated access to the web interface, the probability of exploitation depends on the attacker's ability to compromise user credentials. No EPSS score is available, and the issue is not listed in CISA KEV, but the potential impact of script execution across affected users warrants prompt remediation.
OpenCVE Enrichment