Apache Atlas是美国阿帕奇(Apache)基金会的一套可伸缩和可扩展的核心功能治理服务。 Apache Atlas 0.8版本至2.4.0版本存在代码注入漏洞,该漏洞源于DSL搜索端点接受用户提供的查询字符串,可能导致攻击者修改Gremlin遍历逻辑以访问未授权数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Atlas | 0.8≤ 2.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Atlas | 0.8 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42810 | 9.9 CRITICAL | Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or |
| CVE-2026-42811 | 9.9 CRITICAL | Apache Polaris: could broaden vended GCS credentials through unescaped identifier content |
| CVE-2026-42809 | 9.9 CRITICAL | Apache Polaris: staged table creation could vend storage credentials for unvalidated locat |
| CVE-2026-42812 | 9.9 CRITICAL | Apache Polaris: No protection on `write.metadata.path` |
| CVE-2026-40682 | Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor | |
| CVE-2026-42027 | Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader | |
| CVE-2026-42440 | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader | |
| CVE-2026-29169 | Apache HTTP Server: mod_dav_lock indirect lock crash | |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | |
| CVE-2026-33006 | Apache HTTP Server: mod_auth_digest timing attack | |
| CVE-2026-33007 | Apache HTTP Server: mod_authn_socache crash | |
| CVE-2026-33523 | Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status | |
| CVE-2026-33857 | Apache HTTP Server: Off-by-one OOB reads in AJP getter functions | |
| CVE-2026-34032 | Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination C | |
| CVE-2026-34059 | Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data | |
| CVE-2026-24072 | Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr |
No comments yet