Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2024-23946 Apache OFBiz: Path traversal or file inclusion — Apache OFBizCWE-22 9.1 -2024-02-28
CVE-2024-25065 Apache OFBiz: Path traversal allowing authentication bypass. — Apache OFBizCWE-22 9.1 -2024-02-28
CVE-2024-23807 Apache Xerces C++: Use-after-free on external DTD scan — Apache Xerces C++CWE-416 7.4 -2024-02-28
CVE-2024-26016 Apache Superset: Improper authorization validation on dashboards and charts import — Apache SupersetCWE-863 4.3 Medium2024-02-28
CVE-2024-24779 Apache Superset: Improper data authorization when creating a new dataset — Apache SupersetCWE-863 5.0 Medium2024-02-28
CVE-2024-24772 Apache Superset: Improper Neutralisation of custom SQL on embedded context — Apache SupersetCWE-89 4.3 Medium2024-02-28
CVE-2024-24773 Apache Superset: Improper validation of SQL statements allows for unauthorized access to data — Apache SupersetCWE-863 4.9 Medium2024-02-28
CVE-2024-27315 Apache Superset: Improper error handling on alerts — Apache SupersetCWE-209 4.3 Medium2024-02-28
CVE-2023-50380 Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server — Apache AmbariCWE-611 8.1 -2024-02-27
CVE-2024-21742 Apache James Mime4J: Mime4J DOM header injection — Apache James Mime4JCWE-74 5.3 -2024-02-27
CVE-2024-27905 Apache Aurora: padding oracle can allow construction an authentication cookie — Apache AuroraCWE-200 9.8 -2024-02-27
CVE-2023-51747 SMTP smuggling in Apache James — Apache James serverCWE-20 7.5 -2024-02-27
CVE-2023-51518 Apache James server: Privilege escalation via JMX pre-authentication deserialisation — Apache James serverCWE-502 7.8 -2024-02-27
CVE-2023-50379 Apache Ambari: authenticated users could perform command injection to perform RCE — Apache AmbariCWE-94 9.9 -2024-02-27
CVE-2024-22371 Apache Camel issue on ExchangeCreatedEvent — Apache Camel 2.9 Low2024-02-26
CVE-2024-23320 Apache DolphinScheduler: Arbitrary js execution as root for authenticated users — Apache DolphinSchedulerCWE-20 5.4 -2024-02-23
CVE-2024-22393 Apache Answer: Pixel Flood Attack by uploading the large pixel file — Apache AnswerCWE-434 6.5 -2024-02-22
CVE-2024-23349 Apache Answer: XSS vulnerability when submitting summary — Apache AnswerCWE-79 5.4 -2024-02-22
CVE-2024-26578 Apache Answer: Repeated submission at registration created duplicate users with the same name — Apache AnswerCWE-362 7.4 -2024-02-22
CVE-2024-25141 Apache Airflow Mongo Provider: Certificate validation isn't respected even if SSL is enabled for apache-airflow-providers-mongo — Apache Airflow Mongo ProviderCWE-295 7.5AIHighAI2024-02-20
CVE-2024-23114 Apache Camel: Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository — Apache CamelCWE-502 9.8 -2024-02-20
CVE-2024-22369 Apache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepository — Apache CamelCWE-502 9.8 -2024-02-20
CVE-2023-51770 Apache DolphinScheduler: Arbitrary File Read Vulnerability — Apache DolphinSchedulerCWE-94 7.5AIHighAI2024-02-20
CVE-2023-50270 Apache DolphinScheduler: Session do not expire after password change — Apache DolphinSchedulerCWE-613 9.1AICriticalAI2024-02-20
CVE-2023-49250 Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil — Apache DolphinSchedulerCWE-295 7.4AIHighAI2024-02-20
CVE-2023-49109 Remote Code Execution in Apache Dolphinscheduler — Apache DolphinSchedulerCWE-94 9.8AICriticalAI2024-02-20
CVE-2024-25710 Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file — Apache Commons CompressCWE-835 8.1 High2024-02-19
CVE-2024-26308 Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file — Apache Commons CompressCWE-770 7.5 -2024-02-19
CVE-2024-23952 Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104) — Apache SupersetCWE-400 6.5 Medium2024-02-14
CVE-2023-50291 Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords — Apache SolrCWE-522 7.5 -2024-02-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.