imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2013-4246
High 8.8

libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.

apache subversion
0.03EPSS
CVE-2015-4928
Medium 4.3

Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields.

apache ambari
0.03EPSS
CVE-2018-1294
High 7.5

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users…

apache commons_email
0.03EPSS
CVE-2021-26544
Medium 5.4

Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in L…

apache livy
0.03EPSS
CVE-2013-1968
Medium 5.5

Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.

apache subversion · canonical ubuntu_linux · collabnet subversion · opensuse opensuse
0.03EPSS
CVE-2020-1933
Medium 6.1

A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.

apache nifi
0.03EPSS
CVE-2017-7684
High 7.5

Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server.

apache openmeetings
0.03EPSS
CVE-2009-1275
Medium 6.8

Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive informati…

apache tiles
0.03EPSS
CVE-2021-26559
Medium 6.5

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`…

apache airflow
0.03EPSS
CVE-2019-12413
Medium 5.3

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

apache superset
0.03EPSS
CVE-2006-6589
Medium 6.8

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue tha…

apache ofbiz · apache opentaps
0.03EPSS
CVE-2023-35797
Critical 9.8

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal pa…

apache apache-airflow-providers-apache-hive
0.03EPSS
CVE-2021-28544
Medium 4.3

Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with a…

apache subversion · apple macos · debian debian_linux · fedoraproject fedora
0.03EPSS
CVE-2019-12414
Medium 5.3

In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

apache superset
0.03EPSS
CVE-2017-5649
High 7.5

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL q…

apache geode
0.03EPSS
CVE-2022-45462
Critical 9.8

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher

apache dolphinscheduler
0.03EPSS
CVE-2010-3872
High 7.5

A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.

apache mod_fcgid
0.03EPSS
CVE-2023-28706
Critical 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.

apache airflow_hive_provider
0.03EPSS
CVE-2020-9485
Medium 6.1

An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.

apache airflow
0.03EPSS
CVE-2018-17193
Medium 6.1

The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache Ni…

apache nifi
0.03EPSS
CVE-2021-38555
Critical 9.1

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to int…

apache any23
0.03EPSS
CVE-2021-28657
Medium 5.5

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

apache tika · oracle communications_messaging_server · oracle healthcare_foundation · oracle primavera_unifier · and 1 more
0.03EPSS
CVE-2019-10083
Medium 5.3

When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user …

apache nifi
0.03EPSS
CVE-2022-23913
High 7.5

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

apache artemis · netapp active_iq_unified_manager · netapp oncommand_workflow_automation
0.03EPSS
CVE-2025-46701
High 7.3

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0…

apache tomcat
0.03EPSS