imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2018-8042
High 8.1

Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive and Oozie.

apache ambari
0.02EPSS
CVE-2022-41131
High 7.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG …

apache airflow · apache apache-airflow-providers-apache-hive
0.02EPSS
CVE-2022-37865
Critical 9.1

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the targe…

apache ivy
0.02EPSS
CVE-2017-12613
High 7.1

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing t…

apache portable_runtime · debian debian_linux · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · and 7 more
0.02EPSS
CVE-2025-32897
Critical 9.8

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubatin…

apache seata
0.02EPSS
CVE-2022-24969
Medium 6.1

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.

apache dubbo
0.02EPSS
CVE-2024-41937
Medium 6.1

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web s…

apache airflow
0.02EPSS
CVE-2020-13922
Medium 6.5

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

apache dolphinscheduler
0.02EPSS
CVE-2024-29133
Medium 5.4

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

apache commons_configuration · fedoraproject fedora
0.02EPSS
CVE-2024-39877
High 8.8

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Secur…

apache airflow
0.02EPSS
CVE-2021-41571
Medium 6.5

In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, …

apache pulsar
0.02EPSS
CVE-2024-31865
Medium 6.5

Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or improper privileges so that the notebook can run with the privileges. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users ar…

apache zeppelin
0.02EPSS
CVE-2022-35724
High 7.5

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro versio…

apache avro
0.02EPSS
CVE-2024-36387
Medium 5.4

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

apache http_server · netapp ontap
0.02EPSS
CVE-2023-44981
Critical 9.1

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication I…

apache zookeeper · debian debian_linux
0.02EPSS
CVE-2021-45230
Medium 6.5

In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on DAG Runs can create Dag Runs for dags that they don't have "edit" permissions for.

apache airflow
0.02EPSS
CVE-2024-38286
High 8.6

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time…

apache tomcat · netapp ontap_tools
0.02EPSS
CVE-2024-28098
Medium 6.4

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations should be restricted to users with the tenant admin role or super…

apache pulsar
0.02EPSS
CVE-2023-34434
High 7.5

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are adv…

apache inlong
0.02EPSS
CVE-2021-44145
Medium 6.5

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.

apache nifi
0.02EPSS
CVE-2024-23952
Medium 6.5

This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This…

apache superset
0.02EPSS
CVE-2020-15250
Medium 4.4

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files an…

apache pluto · debian debian_linux · junit junit4 · oracle communications_cloud_native_core_policy
0.02EPSS
CVE-2022-27949
High 7.5

A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apach…

apache airflow
0.02EPSS
CVE-2024-45034
High 8.8

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by the scheduler, where the scheduler is not supposed to execute code submitted by the DAG author. Users are advised…

apache airflow
0.02EPSS
CVE-2024-52318
Medium 6.1

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.

apache tomcat
0.02EPSS