imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2025-23184
Medium 5.9

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies t…

apache cxf
0.02EPSS
CVE-2022-38398
Medium 5.3

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.

apache batik · debian debian_linux
0.02EPSS
CVE-2022-26477
High 7.5

The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and wri…

apache systemds
0.02EPSS
CVE-2023-26031
High 7.5

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root p…

apache hadoop
0.02EPSS
CVE-2017-5663
High 8.8

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is n…

apache fineract
0.02EPSS
CVE-2021-45458
High 7.5

Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlacehold…

apache kylin
0.02EPSS
CVE-2025-54539
Critical 9.8

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers …

apache activemq_nms_amqp
0.02EPSS
CVE-2013-6480
Low 2.1

Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.

apache libcloud
0.02EPSS
CVE-2017-12622
High 7.1

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluster members even without CLUSTER:MANAGE pr…

apache geode
0.02EPSS
CVE-2021-25640
Medium 6.1

In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.

apache dubbo
0.02EPSS
CVE-2016-6815
Medium 6.5

In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

apache ranger
0.02EPSS
CVE-2023-30776
Medium 4.9

An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.

apache superset
0.02EPSS
CVE-2019-17555
High 7.5

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the header, then it can help to implement a DoS…

apache olingo
0.02EPSS
CVE-2014-4651
Critical 9.8

It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.

apache jclouds
0.02EPSS
CVE-2023-28707
High 7.5

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider.This issue affects Apache Airflow Drill Provider: before 2.3.2.

apache apache-airflow-providers-apache-drill
0.02EPSS
CVE-2017-5655
Medium 6.5

In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.

apache ambari
0.02EPSS
CVE-2023-34478
Critical 9.8

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update …

apache shiro
0.02EPSS
CVE-2024-29131
High 7.3

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

apache commons_configuration · fedoraproject fedora · netapp ontap_tools · netapp snapcenter
0.02EPSS
CVE-2017-3154
High 7.5

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

apache atlas
0.02EPSS
CVE-2017-3155
Medium 6.1

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

apache atlas
0.02EPSS
CVE-2022-23974
High 7.5

In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disru…

apache pinot
0.02EPSS
CVE-2019-0202
High 7.5

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be access…

apache storm
0.02EPSS
CVE-2017-17835
High 8.8

In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

apache airflow
0.02EPSS
CVE-2021-41766
High 8.1

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation…

apache karaf
0.02EPSS
CVE-2024-52317
Medium 6.5

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 throu…

apache tomcat
0.02EPSS