Apache Nutch 服务器(Nutch REST API)中存在“缺少授权、不当的资源关闭和任务中断”漏洞。 受影响版本 该问题影响 Apache Nutch 1.10 至 1.22 版本。 建议措施 建议用户升级到 1.23 版本,该版本已移除 Nutch 服务器(Nutch Server)。 若无法升级,则必须将运行 Nutch 服务的实例访问权限限制为仅受信任的用户可访问。 请访问 Apache Nutch 安全公告 获取更多信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Nutch | 1.10 ~ 1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73334 | Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that sk | |
| CVE-2026-41871 | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST A | |
| CVE-2026-41870 | Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Serv | |
| CVE-2026-65181 | Apache Impala: RCE via External Data Source Class Loading | |
| CVE-2026-57866 | Apache Impala: Secrets Exfiltration via SSRF | |
| CVE-2026-56207 | Apache Impala: SAML authentication bypass via forged bearer token | |
| CVE-2026-54048 | Apache Impala: Avro Schema URL Server-Side Request Forgery |
No comments yet