Apache hbase是美国Apache基金会开源的一个分布式NoSQL数据库。 Apache HBase 3.0.0-alpha-1至3.0.0-beta-1版本、2.6.0至2.6.5版本、2.5.0至2.5.14版本和2.4.*及之前版本存在授权问题漏洞,该漏洞源于thrift/rest delegation服务中fetch和close步骤缺少owner检查,导致授权缺失,用户可获取其他用户打开的扫描仪的行,并关闭其他用户的扫描仪。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache HBase | ≤ 2.5.14 |
affected |
2.6-alpha≤ 2.6.5 |
affected | ||
3-alpha≤ 3.0.0-beta-1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache HBase | 0 ~ 2.5.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46452 | Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure | |
| CVE-2026-45816 | Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request | |
| CVE-2026-45815 | Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler | |
| CVE-2026-45813 | Apache NimBLE: Incorrect data validation in BASS add/modify source operation | |
| CVE-2026-45812 | Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler | |
| CVE-2026-45811 | Apache NimBLE: Buffer overflow in socket HCI transport | |
| CVE-2026-66144 | Apache Neethi: Remote PolicyReference fetch lacks resource bounds | |
| CVE-2026-66143 | Apache Neethi: Missing global alternative-output budget across policy computation paths | |
| CVE-2026-66142 | Apache Neethi: Uncontrolled recursion in policy processing | |
| CVE-2026-63317 | Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor X |
No comments yet