Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2024-28148 Apache Superset: Incorrect datasource authorization on explore REST API — Apache SupersetCWE-863 4.3 Medium2024-05-07
CVE-2023-35701 Apache Hive: Arbitrary command execution via JDBC driver — Apache HiveCWE-94 8.8AIHighAI2024-05-03
CVE-2024-32638 Apache APISIX: Forward-Auth Request Smuggling — Apache APISIXCWE-444 9.1 -2024-05-02
CVE-2024-32114 Apache ActiveMQ: Jolokia and REST API were not secured with default configuration — Apache ActiveMQCWE-1188 8.5 High2024-05-02
CVE-2024-27349 Apache HugeGraph-Server: Bypass whitelist in Auth mode — Apache HugeGraph-ServerCWE-290 9.1 -2024-04-22
CVE-2024-27348 Apache HugeGraph-Server: Command execution in gremlin — Apache HugeGraph-Server 9.8 -2024-04-22
CVE-2024-27347 Apache HugeGraph-Hubble: SSRF in Hubble connection page — Apache HugeGraph-HubbleCWE-918 9.1 -2024-04-22
CVE-2024-29733 Apache Airflow FTP Provider: FTP_TLS instance with unverified SSL context — Apache Airflow FTP ProviderCWE-295 7.5 -2024-04-21
CVE-2024-29217 Apache Answer: XSS vulnerability when changing personal website — Apache AnswerCWE-79 5.4 -2024-04-21
CVE-2024-31869 Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used — Apache AirflowCWE-200 6.5 -2024-04-18
CVE-2024-31391 Apache Solr Operator: Solr-Operator liveness and readiness probes may leak basic auth credentials — Apache Solr OperatorCWE-532 7.5 -2024-04-12
CVE-2024-27309 Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode — Apache KafkaCWE-863 4.4 -2024-04-12
CVE-2024-31309 Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack — Apache Traffic ServerCWE-20 7.5 -2024-04-10
CVE-2024-31867 Apache Zeppelin: LDAP search filter query Injection Vulnerability — Apache ZeppelinCWE-20 9.8AICriticalAI2024-04-09
CVE-2024-31868 Apache Zeppelin: XSS vulnerability in the helium module — Apache ZeppelinCWE-79 5.4AIMediumAI2024-04-09
CVE-2024-31866 Apache Zeppelin: Interpreter download command does not escape malicious code injection — Apache ZeppelinCWE-116 9.8AICriticalAI2024-04-09
CVE-2024-31865 Apache Zeppelin: Cron arbitrary user impersonation with improper privileges — Apache ZeppelinCWE-20 9.8AICriticalAI2024-04-09
CVE-2024-31864 Apache Zeppelin: Remote code execution by adding malicious JDBC connection string — Apache ZeppelinCWE-94 9.8AICriticalAI2024-04-09
CVE-2024-31863 Apache Zeppelin: Replacing other users notebook, bypassing any permissions — Apache ZeppelinCWE-290 9.1AICriticalAI2024-04-09
CVE-2024-31862 Apache Zeppelin: Denial of service with invalid notebook name — Apache ZeppelinCWE-20 9.1AICriticalAI2024-04-09
CVE-2022-47894 Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE — Apache Zeppelin SAPCWE-20 7.5AIHighAI2024-04-09
CVE-2021-28656 Apache Zeppelin: CSRF vulnerability in the Credentials page — Apache ZeppelinCWE-352 8.8AIHighAI2024-04-09
CVE-2024-31860 Apache Zeppelin: Path traversal vulnerability — Apache ZeppelinCWE-22 6.5AIMediumAI2024-04-09
CVE-2024-24746 Apache NimBLE: Denial of service in NimBLE Bluetooth stack — Apache NimBLECWE-835 6.5 -2024-04-06
CVE-2024-27316 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames — Apache HTTP ServerCWE-770 7.5 -2024-04-04
CVE-2024-24795 Apache HTTP Server: HTTP Response Splitting in multiple modules — Apache HTTP ServerCWE-113 9.1 -2024-04-04
CVE-2023-38709 Apache HTTP Server: HTTP response splitting — Apache HTTP Server 7.5 -2024-04-04
CVE-2024-29008 Apache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instance — Apache CloudStackCWE-20 9.6 -2024-04-04
CVE-2024-29007 Apache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences — Apache CloudStackCWE-918 8.1 -2024-04-04
CVE-2024-29006 Apache CloudStack: x-forwarded-for HTTP header parsed by default — Apache CloudStackCWE-290 8.1 -2024-04-04

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.