imPC@ndo IT

Apache vulnerabilities

3268 CVE

CVE-2024-31860
Medium 6.5

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0…

apache zeppelin
0.01EPSS
CVE-2022-43670
Medium 5.4

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the t…

apache sling_cms
0.01EPSS
CVE-2022-34271
High 8.8

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

apache atlas
0.01EPSS
CVE-2022-40954
Medium 5.5

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files…

apache airflow · apache apache-airflow-providers-apache-spark
0.01EPSS
CVE-2023-25695
Medium 5.3

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.

apache airflow
0.01EPSS
CVE-2022-46769
Medium 5.4

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the s…

apache sling_cms
0.01EPSS
CVE-2023-37536
High 8.2

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

apache xerces-c\+\+ · fedoraproject fedora · hcltech bigfix_platform
0.01EPSS
CVE-2022-43766
High 7.5

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to a…

apache iotdb
0.01EPSS
CVE-2026-28780
Critical 9.8

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after …

apache http_server
0.01EPSS
CVE-2021-39234
Medium 6.8

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

apache ozone
0.01EPSS
CVE-2023-40273
High 8.0

The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session…

apache airflow
0.01EPSS
CVE-2024-31862
Medium 5.3

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

apache zeppelin
0.01EPSS
CVE-2024-29834
Medium 6.4

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the t…

apache pulsar
0.01EPSS
CVE-2017-9797
Medium 6.5

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, a…

apache geode
0.01EPSS
CVE-2018-11774
High 7.2

Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin…

apache virtual_computing_lab
0.01EPSS
CVE-2018-11772
High 7.2

Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to th…

apache virtual_computing_lab
0.01EPSS
CVE-2023-31066
Critical 9.1

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are a…

apache inlong
0.01EPSS
CVE-2022-40309
Medium 4.3

Users with write permissions to a repository can delete arbitrary directories.

apache archiva
0.01EPSS
CVE-2010-3718
Low 1.2

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstra…

apache tomcat
0.01EPSS
CVE-2023-37544
High 7.5

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2…

apache pulsar
0.01EPSS
CVE-2020-1932
Medium 6.5

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint…

apache superset
0.01EPSS
CVE-2023-49735
High 7.5

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data…

apache tiles
0.01EPSS
CVE-2024-28746
High 8.1

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airf…

apache airflow
0.01EPSS
CVE-2023-47265
Medium 5.4

Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of th…

apache airflow
0.01EPSS
CVE-2021-41832
High 7.5

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.

apache openoffice
0.01EPSS