imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2022-32533
Critica 9.8

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dor…

apache jetspeed
0.04EPSS
CVE-2020-13941
Alta 8.8

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler) allows commands backup, re…

apache solr
0.04EPSS
CVE-2002-1895
Media 5.0

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.

apache tomcat
0.04EPSS
CVE-2022-29063
Critica 9.8

The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or …

apache ofbiz
0.04EPSS
CVE-2017-3161
Media 6.1

The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.

apache hadoop
0.04EPSS
CVE-2012-5650
Media 4.3

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.

apache couchdb
0.04EPSS
CVE-2016-8744
Alta 8.8

Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0.10.0, SnakeYAML will allow unmarshallin…

apache brooklyn
0.04EPSS
CVE-2021-33036
Alta 8.8

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

apache hadoop
0.04EPSS
CVE-2019-0200
Alta 7.5

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance by sending specially crafted commands using AMQP protocol versions below 1.0 (A…

apache qpid_broker-j
0.04EPSS
CVE-2002-0493
Alta 7.5

Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.

apache tomcat
0.04EPSS
CVE-2016-4462
Alta 8.8

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mi…

apache ofbiz
0.04EPSS
CVE-2021-27737
Alta 7.5

Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

apache traffic_server
0.04EPSS
CVE-2010-2232
Alta 7.5

In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.

apache derby
0.04EPSS
CVE-2019-0212
Alta 7.5

In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not w…

apache hbase
0.04EPSS
CVE-2016-5425
Alta 7.8

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership i…

apache tomcat
0.04EPSS
CVE-2022-23945
Alta 7.5

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

apache shenyu
0.04EPSS
CVE-2014-3624
Critica 9.8

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.

apache traffic_server
0.04EPSS
CVE-2010-1151
Media 6.8

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of crede…

apache apache_http_server
0.04EPSS
CVE-2019-15544
Alta 7.5

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

apache hbase · rust-protobuf_project rust-protobuf
0.04EPSS
CVE-2020-11976
Alta 7.5

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions …

apache fortress · apache wicket
0.04EPSS
CVE-2017-3160
Alta 7.4

After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle…

apache cordova
0.04EPSS
CVE-2014-3501
Media 4.3

Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.

apache cordova
0.04EPSS
CVE-2016-15057
Critica 9.9

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can …

apache continuum
0.04EPSS
CVE-2018-11767
Alta 7.4

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.

apache hadoop
0.04EPSS
CVE-1999-0289
Media 5.0

The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.

apache http_server
0.04EPSS