imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2021-39231
Critica 9.1

In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.

apache ozone
0.02EPSS
CVE-2016-6801
Alta 8.8

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows rem…

apache jackrabbit · debian debian_linux
0.02EPSS
CVE-2015-5241
Media 6.1

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portle…

apache juddi
0.02EPSS
CVE-2023-39553
Alta 7.5

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with Drill…

apache apache-airflow-providers-apache-drill
0.02EPSS
CVE-2021-31164
Alta 7.5

Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

apache unomi
0.02EPSS
CVE-2022-24289
Alta 8.8

Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Object Persistence (ROP) feature is a web services-based technology that provides object persistence and query functionality to 'remote' appli…

apache cayenne
0.02EPSS
CVE-2026-35152
Alta 8.8

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authen…

apache fineract
0.02EPSS
CVE-2023-25754
Critica 9.8

Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.

apache airflow
0.02EPSS
CVE-2022-31780
Alta 7.5

Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

apache traffic_server · debian debian_linux · fedoraproject fedora
0.02EPSS
CVE-2014-3526
Alta 7.5

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.

apache wicket
0.02EPSS
CVE-2022-32549
Media 5.3

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

apache sling_api · apache sling_commons_log
0.02EPSS
CVE-2022-45378
Critica 9.8

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath…

apache soap
0.02EPSS
CVE-2018-8016
Critica 9.8

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225.…

apache cassandra
0.02EPSS
CVE-2020-17517
Alta 7.5

The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthori…

apache ozone
0.02EPSS
CVE-2021-36162
Alta 8.8

Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order t…

apache dubbo
0.02EPSS
CVE-2019-10080
Media 6.5

The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of…

apache nifi
0.02EPSS
CVE-2022-24948
Media 6.1

A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information ab…

apache jspwiki
0.02EPSS
CVE-2023-38435
Media 6.1

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.…

apache felix_health_check_webconsole_plugin
0.02EPSS
CVE-2006-6588
Alta 7.5

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of conten…

apache ofbiz
0.02EPSS
CVE-2016-1000104
Alta 8.8

A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.

apache mod_fcgid · opensuse leap · opensuse opensuse
0.02EPSS
CVE-2017-3165
Media 5.4

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper escaping of se…

apache brooklyn
0.02EPSS
CVE-2022-40955
Alta 8.8

In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leadin…

apache inlong
0.02EPSS
CVE-2021-24117
Media 4.9

In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in is…

apache teaclave_sgx_sdk
0.02EPSS
CVE-2020-23922
Alta 7.1

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

apache bookkeeper · giflib_project giflib
0.02EPSS
CVE-2016-1566
Media 5.4

Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. N…

apache guacamole
0.02EPSS