imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2021-25958
Media 6.5

In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he …

apache ofbiz
0.03EPSS
CVE-2012-3376
Alta 7.5

DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to w…

apache hadoop
0.03EPSS
CVE-2023-39508
Alta 8.8

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It…

apache airflow
0.03EPSS
CVE-2016-6811
Alta 8.8

In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

apache hadoop
0.03EPSS
CVE-2017-7677
Media 5.9

In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table.

apache ranger
0.03EPSS
CVE-2010-2952
Media 4.3

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poiso…

apache traffic_server
0.03EPSS
CVE-2022-30126
Media 5.5

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtracting…

apache tika · oracle primavera_unifier
0.03EPSS
CVE-2020-9482
Media 6.5

If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be use…

apache nifi_registry
0.03EPSS
CVE-2016-5394
Media 6.1

In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough and for some input patterns allows script tags to pass through unencoded, leading to potential XSS vulnerabilit…

apache sling
0.03EPSS
CVE-2016-0731
Media 4.9

The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.

apache ambari
0.03EPSS
CVE-2021-45229
Media 6.1

It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.

apache airflow
0.03EPSS
CVE-2017-12607
Alta 7.8

A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execut…

apache openoffice · debian debian_linux
0.03EPSS
CVE-2021-4040
Media 5.3

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of malic…

apache artemis · redhat amq_broker
0.03EPSS
CVE-2020-13928
Media 6.1

Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability.

apache atlas
0.03EPSS
CVE-2016-6799
Alta 7.5

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximu…

apache cordova
0.03EPSS
CVE-2021-42357
Media 6.1

When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by a…

apache knox
0.03EPSS
CVE-2018-11787
Alta 8.1

In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the co…

apache karaf
0.03EPSS
CVE-2022-40664
Critica 9.8

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

apache shiro
0.03EPSS
CVE-2023-40743
Critica 9.8

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted i…

apache axis
0.03EPSS
CVE-2024-55633
Media 6.5

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres an…

apache superset
0.03EPSS
CVE-2022-26650
Alta 7.5

In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions …

apache shenyu
0.03EPSS
CVE-2009-5004
Media 6.5

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

apache qpid-cpp
0.03EPSS
CVE-2021-27738
Alta 7.5

All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning…

apache kylin
0.03EPSS
CVE-2014-7807
Media 5.0

Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.

apache cloudstack
0.03EPSS
CVE-2022-45875
Critica 9.8

Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be…

apache dolphinscheduler
0.03EPSS