Apache Nutch 服务器(Nutch REST API)中存在以下漏洞: 缺少授权验证 代码生成控制不当(“代码注入”) 动态管理的代码资源控制不当 使用外部可控输入来选择类或代码(“不安全的反射”) 影响范围: 该问题影响 Apache Nutch 的 1.11 至 1.22 版本。 建议措施: 首选方案:用户建议升级到 1.23 版本,该版本已移除 Nutch 服务器组件。 替代方案:如果无法升级,用户必须限制对运行 Nutch 服务的实例的访问权限,仅允许受信任的用户访问。 同时,请访问 Apache
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Nutch | 1.11 ~ 1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74761 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscripti | |
| CVE-2026-73334 | Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that sk | |
| CVE-2026-41871 | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST A | |
| CVE-2026-41869 | Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch | |
| CVE-2026-65181 | Apache Impala: RCE via External Data Source Class Loading | |
| CVE-2026-57866 | Apache Impala: Secrets Exfiltration via SSRF | |
| CVE-2026-56207 | Apache Impala: SAML authentication bypass via forged bearer token | |
| CVE-2026-54048 | Apache Impala: Avro Schema URL Server-Side Request Forgery |
No comments yet