imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2022-31778
Alta 7.5

Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

apache traffic_server · debian debian_linux
0.02EPSS
CVE-2020-17508
Alta 7.5

The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

apache traffic_server
0.02EPSS
CVE-2018-11802
Media 4.3

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and serve…

apache solr
0.02EPSS
CVE-2017-12614
Media 6.1

It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: …

apache airflow
0.02EPSS
CVE-2020-13952
Alta 8.1

In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata …

apache superset
0.02EPSS
CVE-2010-4408
Media 6.8

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileg…

apache archiva
0.02EPSS
CVE-2019-17560
Critica 9.1

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" v…

apache netbeans · oracle graalvm
0.02EPSS
CVE-2023-30631
Alta 7.5

Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.Thi…

apache traffic_server · debian debian_linux · fedoraproject fedora
0.02EPSS
CVE-2017-15696
Alta 7.5

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and…

apache geode
0.02EPSS
CVE-2022-47185
Alta 7.5

Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

apache traffic_server
0.02EPSS
CVE-2018-8031
Media 6.1

The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically used to add TomEE features to a Tomcat installation. The TomEE bundles do not sh…

apache tomee
0.02EPSS
CVE-2011-2177
Alta 7.8

OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.

apache openoffice
0.02EPSS
CVE-2022-38648
Media 5.3

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.

apache batik · debian debian_linux
0.02EPSS
CVE-2009-3821
Media 4.3

Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

apache solr
0.02EPSS
CVE-2023-27602
Critica 9.8

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the fi…

apache linkis
0.02EPSS
CVE-2017-7683
Alta 7.5

Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.

apache openmeetings
0.02EPSS
CVE-2021-44040
Alta 7.5

Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

apache traffic_server · debian debian_linux
0.02EPSS
CVE-2016-6805
Media 5.9

Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.

apache ignite
0.02EPSS
CVE-2018-1314
Media 4.3

In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.

apache hive
0.02EPSS
CVE-2018-1338
Media 5.5

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.

apache tika
0.02EPSS
CVE-2025-22828
Media 4.3

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can…

apache cloudstack
0.02EPSS
CVE-2021-43980
Bassa 3.7

The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0…

apache tomcat · debian debian_linux
0.02EPSS
CVE-2023-25696
Critica 9.8

Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

apache apache-airflow-providers-apache-hive
0.02EPSS
CVE-2025-68675
Alta 7.5

In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatical…

apache airflow
0.02EPSS
CVE-2022-23206
Alta 7.5

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.

apache traffic_control
0.02EPSS