Apache Nutch 服务器(Nutch REST API)中存在“缺少授权”及“使用外部可控输入来选择类或代码(‘不安全的反射’)”漏洞。 该问题影响 Apache Nutch 1.10 至 1.22 版本。 建议用户升级至 1.23 版本,该版本已移除 Nutch Server。如果无法升级,则必须限制运行 Nutch 服务的实例仅允许受信任的用户访问。 请访问 Apache Nutch 安全公告页面获取更多信息:https://nutch.apache.org/documentation/security
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Nutch | 1.10 ~ 1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74761 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscripti | |
| CVE-2026-73334 | Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that sk | |
| CVE-2026-41869 | Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch | |
| CVE-2026-41870 | Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Serv | |
| CVE-2026-65181 | Apache Impala: RCE via External Data Source Class Loading | |
| CVE-2026-57866 | Apache Impala: Secrets Exfiltration via SSRF | |
| CVE-2026-56207 | Apache Impala: SAML authentication bypass via forged bearer token | |
| CVE-2026-54048 | Apache Impala: Avro Schema URL Server-Side Request Forgery |
No comments yet