Apache Aurora是美国阿帕奇(Apache)基金会的一个用于长时间运行的服务和 cron 作业的 Mesos 框架。 Apache Aurora 0.5.0及之后版本存在信息泄露漏洞,该漏洞源于允许未经授权的攻击者获取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Aurora | 0.5.0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-50379 | Apache Ambari: authenticated users could perform command injection to perform RCE | |
| CVE-2023-51518 | Apache James server: Privilege escalation via JMX pre-authentication deserialisation | |
| CVE-2023-51747 | SMTP smuggling in Apache James | |
| CVE-2024-21742 | Apache James Mime4J: Mime4J DOM header injection | |
| CVE-2023-50380 | Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server |
No comments yet