imPC@ndo EN

Vulnerabilità Apache

3268 CVE

CVE-2024-31860
Media 6.5

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files in the filesystem that the server account can access.  This issue affects Apache Zeppelin: from 0.9.0 before 0…

apache zeppelin
0.01EPSS
CVE-2022-43670
Media 5.4

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the t…

apache sling_cms
0.01EPSS
CVE-2022-34271
Alta 8.8

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

apache atlas
0.01EPSS
CVE-2022-40954
Media 5.5

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files…

apache airflow · apache apache-airflow-providers-apache-spark
0.01EPSS
CVE-2023-25695
Media 5.3

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.

apache airflow
0.01EPSS
CVE-2022-46769
Media 5.4

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the s…

apache sling_cms
0.01EPSS
CVE-2023-37536
Alta 8.2

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

apache xerces-c\+\+ · fedoraproject fedora · hcltech bigfix_platform
0.01EPSS
CVE-2022-43766
Alta 7.5

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to a…

apache iotdb
0.01EPSS
CVE-2026-28780
Critica 9.8

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after …

apache http_server
0.01EPSS
CVE-2021-39234
Media 6.8

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.

apache ozone
0.01EPSS
CVE-2023-40273
Alta 8.0

The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session…

apache airflow
0.01EPSS
CVE-2024-31862
Media 5.3

Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.

apache zeppelin
0.01EPSS
CVE-2024-29834
Media 6.4

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the t…

apache pulsar
0.01EPSS
CVE-2017-9797
Media 6.5

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, a…

apache geode
0.01EPSS
CVE-2018-11774
Alta 7.2

Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin…

apache virtual_computing_lab
0.01EPSS
CVE-2018-11772
Alta 7.2

Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to th…

apache virtual_computing_lab
0.01EPSS
CVE-2023-31066
Critica 9.1

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are a…

apache inlong
0.01EPSS
CVE-2022-40309
Media 4.3

Users with write permissions to a repository can delete arbitrary directories.

apache archiva
0.01EPSS
CVE-2010-3718
Bassa 1.2

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstra…

apache tomcat
0.01EPSS
CVE-2023-37544
Alta 7.5

Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 through 2.9.*, from 2…

apache pulsar
0.01EPSS
CVE-2020-1932
Media 6.5

An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint…

apache superset
0.01EPSS
CVE-2023-49735
Alta 7.5

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data…

apache tiles
0.01EPSS
CVE-2024-28746
Alta 8.1

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airf…

apache airflow
0.01EPSS
CVE-2023-47265
Media 5.4

Apache Airflow, versions 2.6.0 through 2.7.3 has a stored XSS vulnerability that allows a DAG author to add an unbounded and not-sanitized javascript in the parameter description field of the DAG. This Javascript can be executed on the client side of any of th…

apache airflow
0.01EPSS
CVE-2021-41832
Alta 7.5

It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.

apache openoffice
0.01EPSS