Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2024-29834 Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints — Apache PulsarCWE-863 6.4 Medium2024-04-02
CVE-2024-23537 Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. — Apache FineractCWE-269 8.4 High2024-03-29
CVE-2024-23538 Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. — Apache FineractCWE-89 9.9 Critical2024-03-29
CVE-2024-23539 Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. — Apache FineractCWE-89 8.3 High2024-03-29
CVE-2024-29735 Apache Airflow: Potentially harmful permission changing by log task handler — Apache AirflowCWE-281 8.1AIHighAI2024-03-26
CVE-2024-27438 Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution — Apache DorisCWE-494 8.8AIHighAI2024-03-21
CVE-2024-26307 Apache Doris: Possible race condition — Apache DorisCWE-362 6.5AIMediumAI2024-03-21
CVE-2024-29131 Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() — Apache Commons ConfigurationCWE-787 9.8AICriticalAI2024-03-21
CVE-2024-29133 Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree — Apache Commons ConfigurationCWE-787 9.8AICriticalAI2024-03-21
CVE-2024-27439 Apache Wicket: Possible bypass of CSRF protection — Apache WicketCWE-352 8.8 -2024-03-19
CVE-2024-24683 Apache Hop Engine: ID isn't escaped when generating HTML — Apache Hop EngineCWE-20 8.2AIHighAI2024-03-19
CVE-2024-28752 Apache CXF SSRF Vulnerability using the Aegis databinding — Apache CXFCWE-918 9.1 -2024-03-15
CVE-2024-23944 Apache ZooKeeper: Information disclosure in persistent watcher handling — Apache ZooKeeperCWE-862 5.3 -2024-03-15
CVE-2024-28746 Apache Airflow: Ignored Airflow Permissions — Apache AirflowCWE-281 4.3AIMediumAI2024-03-14
CVE-2024-23672 Apache Tomcat: WebSocket DoS with incomplete closing handshake — Apache TomcatCWE-459 7.5AIHighAI2024-03-13
CVE-2024-24549 Apache Tomcat: HTTP/2 header handling DoS — Apache TomcatCWE-20 7.5AIHighAI2024-03-13
CVE-2024-27894 Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying — Apache PulsarCWE-20 8.5 High2024-03-12
CVE-2024-27317 Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification — Apache PulsarCWE-22 8.4 High2024-03-12
CVE-2024-27135 Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution — Apache PulsarCWE-913 8.5 High2024-03-12
CVE-2022-34321 Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint — Apache PulsarCWE-306 8.2 High2024-03-12
CVE-2024-28098 Apache Pulsar: Improper Authorization For Topic-Level Policy Management — Apache PulsarCWE-863 6.4 Medium2024-03-12
CVE-2023-41313 Apache Doris: Timing Attack weakness — Apache DorisCWE-208 5.9AIMediumAI2024-03-12
CVE-2023-50740 Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged — Apache Linkis DataSourceCWE-532 7.5AIHighAI2024-03-06
CVE-2024-26580 Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability — Apache InLongCWE-502 9.1AICriticalAI2024-03-06
CVE-2024-27138 Apache Archiva: disabling user registration is not effective — Apache ArchivaCWE-863 7.5 -2024-03-01
CVE-2024-27139 Apache Archiva: incorrect authentication potentially leading to account takeover — Apache ArchivaCWE-863 9.1 -2024-03-01
CVE-2024-27140 Apache Archiva: reflected XSS — Apache ArchivaCWE-79 6.1 -2024-03-01
CVE-2023-50378 Apache Ambari: Various XSS problems — Apache AmbariCWE-79 6.1 -2024-03-01
CVE-2024-26280 Apache Airflow: Overly broad default permissions for Viewer/Ops (audit logs) — Apache AirflowCWE-276 2.7 -2024-03-01
CVE-2024-27906 Apache Airflow: Dag Code and Import Error Permissions Ignored — Apache AirflowCWE-862 4.3 -2024-02-29

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.