imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2021-45457
High 7.5

In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions…

apache kylin
0.02EPSS
CVE-2022-46364
Critical 9.8

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

apache cxf
0.02EPSS
CVE-2022-34916
Critical 9.8

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JN…

apache flume
0.02EPSS
CVE-2023-34212
Medium 6.5

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of …

apache nifi
0.02EPSS
CVE-2021-38542
Medium 5.9

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.

apache james
0.02EPSS
CVE-2022-41704
High 7.5

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.

apache batik · debian debian_linux
0.02EPSS
CVE-2017-7664
Critical 10.0

Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

apache openmeetings
0.02EPSS
CVE-2022-31779
High 7.5

Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

apache traffic_server · debian debian_linux · fedoraproject fedora
0.02EPSS
CVE-2013-7372
Medium 5.0

The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Archi…

apache harmony · google android
0.02EPSS
CVE-2018-8008
Medium 5.5

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), t…

apache storm
0.02EPSS
CVE-2021-43082
Critical 9.8

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Apache Traffic Server allows an attacker to overwrite memory. This issue affects Apache Traffic Server 9.1.0.

apache traffic_server
0.02EPSS
CVE-2018-1298
Medium 5.9

A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthenticated attac…

apache qpid_broker-j
0.02EPSS
CVE-2015-3186
Low 3.5

Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.

apache ambari
0.02EPSS
CVE-2021-36739
Medium 6.1

The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.

apache pluto
0.02EPSS
CVE-2021-36738
Medium 6.1

The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact

apache pluto
0.02EPSS
CVE-2021-36737
Medium 6.1

The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact

apache pluto
0.02EPSS
CVE-2024-52338
Critical 9.8

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for …

apache arrow
0.02EPSS
CVE-2021-41532
Medium 5.3

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access the data from these endpoints.

apache ozone
0.02EPSS
CVE-2024-23672
Medium 6.3

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, fro…

apache tomcat · debian debian_linux · fedoraproject fedora
0.02EPSS
CVE-2001-0131
Low 3.3

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

apache http_server · debian debian_linux
0.02EPSS
CVE-2018-11777
High 8.1

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.

apache hive
0.02EPSS
CVE-2023-49109
Critical 9.8

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.

apache dolphinscheduler
0.02EPSS
CVE-2023-49898
High 7.2

In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful at…

apache streampark
0.02EPSS
CVE-2022-28129
High 7.5

Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

apache traffic_server · debian debian_linux · fedoraproject fedora
0.02EPSS
CVE-2021-39233
Critical 9.1

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client.

apache ozone
0.02EPSS