imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2018-1307
High 8.1

In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD ty…

apache juddi
0.02EPSS
CVE-2016-0735
High 8.8

Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.

apache ranger
0.02EPSS
CVE-2023-40272
High 7.5

Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade …

apache apache-airflow-providers-apache-spark
0.02EPSS
CVE-2023-46279
Critical 9.8

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

apache dubbo
0.02EPSS
CVE-2023-42781
Medium 6.5

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar o…

apache airflow
0.02EPSS
CVE-2022-29405
Medium 6.5

In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8

apache archiva
0.02EPSS
CVE-2025-27888
Medium 5.4

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue affects…

apache druid
0.02EPSS
CVE-2022-41137
High 8.3

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In rea…

apache hive
0.02EPSS
CVE-2021-32609
Medium 5.4

Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page.

apache superset
0.02EPSS
CVE-2023-46104
Medium 6.5

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

apache superset
0.02EPSS
CVE-2023-46851
Medium 4.9

Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them.  Exposing internal files then can lead to other expl…

apache allura
0.02EPSS
CVE-2017-7673
Critical 9.8

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.

apache openmeetings
0.02EPSS
CVE-2021-34538
High 7.5

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This al…

apache hive
0.02EPSS
CVE-2023-35088
Critical 9.8

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, audit…

apache inlong
0.02EPSS
CVE-2017-7682
High 8.2

Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.

apache openmeetings
0.02EPSS
CVE-2024-23452
High 7.5

Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause Description: The http_parser does not comply with the RFC-7230 HTTP 1.1 specification. Attack scenario: If a m…

apache brpc
0.02EPSS
CVE-2022-38362
High 8.8

Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.

apache apache-airflow-providers-docker
0.02EPSS
CVE-2019-17561
High 7.5

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

apache netbeans · oracle graalvm
0.02EPSS
CVE-2022-40604
High 7.5

In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.

apache airflow
0.02EPSS
CVE-2021-39232
High 8.8

In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.

apache ozone
0.02EPSS
CVE-2025-59118
High 7.3

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue.

apache ofbiz
0.02EPSS
CVE-2016-4467
Medium 5.9

The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when us…

apache qpid_proton
0.02EPSS
CVE-2003-1307
Medium 4.3

The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connecti…

apache http_server
0.02EPSS
CVE-2023-41834
Medium 6.1

Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could …

apache flink_stateful_functions
0.02EPSS
CVE-2024-47208
Critical 9.8

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.

apache ofbiz
0.02EPSS