Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-50292 Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users — Apache SolrCWE-732 9.8 -2024-02-09
CVE-2023-50298 Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions — Apache SolrCWE-200 7.5 -2024-02-09
CVE-2023-50386 Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets — Apache SolrCWE-434 9.8 -2024-02-09
CVE-2024-23452 Apache bRPC: HTTP request smuggling vulnerability — Apache bRPCCWE-444 8.2 -2024-02-08
CVE-2023-39196 Apache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpoints — Apache OzoneCWE-287 5.3 Medium2024-02-07
CVE-2023-51437 Apache Pulsar: Timing attack in SASL token signature verification — Apache PulsarCWE-203 7.4 High2024-02-07
CVE-2024-23673 Apache Sling Servlets Resolver: Malicious code execution via path traversal — Apache Sling Servlets ResolverCWE-22 8.5 High2024-02-06
CVE-2023-44313 Apache ServiceComb Service-Center: attacker can perform SSRF through the frontend API — Apache ServiceComb Service-CenterCWE-918 7.6 High2024-01-31
CVE-2023-44312 Apache ServiceComb Service-Center: attacker can query all environment variables of the service-center server — Apache ServiceComb Service-CenterCWE-200 5.8 Medium2024-01-31
CVE-2023-29055 Apache Kylin: Insufficiently protected credentials in config file — Apache KylinCWE-522 9.8 -2024-01-29
CVE-2023-50944 Apache Airflow: Bypass permission verification to read code of other dags — Apache AirflowCWE-862 6.5 -2024-01-24
CVE-2023-50943 Apache Airflow: Potential pickle deserialization vulnerability in XComs — Apache AirflowCWE-502 8.2 -2024-01-24
CVE-2023-51702 Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service — Apache Airflow CNCF Kubernetes providerCWE-532 6.5 -2024-01-24
CVE-2023-49657 Apache Superset: Stored XSS in Dashboard Title and Chart Title — Apache SupersetCWE-79 9.6 Critical2024-01-23
CVE-2024-21733 Apache Tomcat: Leaking of unrelated request bodies in default error page — Apache TomcatCWE-209 7.5 -2024-01-19
CVE-2023-46226 Apache IoTDB: Remote Code Execution (RCE) risk via the UDF — Apache IoTDB 9.8 -2024-01-15
CVE-2023-46749 Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting — Apache ShiroCWE-22 9.8 -2024-01-15
CVE-2023-50290 Apache Solr: Host environment variables are published via the Metrics API — Apache SolrCWE-200 7.5 -2024-01-15
CVE-2023-49619 Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions. — Apache AnswerCWE-362--AI2024-01-10
CVE-2023-51441 Apache Axis 1.x (EOL) may allow SSRF when untrusted input is passed to the service admin HTTP API — Apache AxisCWE-918 8.7 -2024-01-06
CVE-2023-51784 Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager — Apache InLongCWE-94 9.8AICriticalAI2024-01-03
CVE-2023-51785 Apache InLong: Arbitrary File Read Vulnerability in Apache InLong Manager — Apache InLongCWE-502 7.5AIHighAI2024-01-03
CVE-2023-49299 Apache DolphinScheduler: Arbitrary js execute as root for authenticated users — Apache DolphinSchedulerCWE-20 8.2 -2023-12-30
CVE-2023-47804 Apache OpenOffice: Macro URL arbitrary script execution — Apache OpenOfficeCWE-20 7.8 -2023-12-29
CVE-2023-51467 Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability — Apache OFBiz 9.8AICriticalAI2023-12-26
CVE-2023-50968 Apache OFBiz: Arbitrary file properties reading and SSRF attack — Apache OFBizCWE-200 6.5AIMediumAI2023-12-26
CVE-2023-51656 Apache IoTDB: Unsafe deserialize map in Sync Tool — Apache IoTDBCWE-502 9.8AICriticalAI2023-12-21
CVE-2023-48291 Apache Airflow: Improper access control to DAG resources — Apache AirflowCWE-668 4.3AIMediumAI2023-12-21
CVE-2023-50783 Apache Airflow: Improper access control vulnerability on the "varimport" endpoint — Apache AirflowCWE-284 6.5AIMediumAI2023-12-21
CVE-2023-47265 Apache Airflow: DAG Params alllow to embed unchecked Javascript — Apache AirflowCWE-79 5.4AIMediumAI2023-12-21

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.