Advisories for Maven/Org.apache.atlas/Apache-Atlas package

2026

Apache Atlas has a Code Injection Vulnerability

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas. Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data. Affected Version: This issue affects Apache Atlas: from 0.8-incubating through 2.4.0. For affected versions >= 2.0.0, the vulnerability is only exploitable when Atlas is deployed with below non-default configuration. atlas.dsl.executor.traversal=false Mitigation: Users …

2025
2022
2020