{"id":"CVE-2025-62198","title":"An authenticated user can perform XSS.\n\nThis issue affects Apache Atlas versions 2.4.0 and earlier.\n\nUsers are recommended to upgrade to version 2.5.0, which fixes the issue.","summary":"An authenticated user can perform XSS.\n\nThis issue affects Apache Atlas versions 2.4.0 and earlier.\n\nUsers are recommended to upgrade to version 2.5.0, which fixes the issue.","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-80"],"vendor":"apache","product":"atlas","affected":["atlas < 2.5.0"],"patched":["atlas 2.5.0"],"published":"2026-06-22","updated":"2026-06-23","sourceUpdated":"2026-06-23T14:53:43.500","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-62198","references":[{"url":"https://lists.apache.org/thread/nv893lhz3ok08f25j3v4z1to5nrpdp7k","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/20/1","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-22T15:50:14.516394Z"},"ingestedAt":"2026-09-14T08:45:06.539Z","epss":0.00505,"epssPercentile":0.42032,"slug":"CVE-2025-62198","body":"## Overview\n\nAn authenticated user can perform XSS.\n\nThis issue affects Apache Atlas versions 2.4.0 and earlier.\n\nUsers are recommended to upgrade to version 2.5.0, which fixes the issue.\n\n## Affected\n\n- `atlas < 2.5.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `atlas 2.5.0`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}