Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-48796 Apache dolphinscheduler sensitive information disclosure — Apache DolphinSchedulerCWE-200 7.5 -2023-11-24
CVE-2023-43123 Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files — Apache StormCWE-200 5.5 -2023-11-23
CVE-2023-37924 Apache Submarine: SQL injection from unauthorized login — Apache SubmarineCWE-89 8.8AIHighAI2023-11-22
CVE-2022-46337 Apache Derby: LDAP injection vulnerability in authenticator — Apache Derby 9.8AICriticalAI2023-11-20
CVE-2023-46302 Apache Submarine: Fix CVE-2022-1471 SnakeYaml unsafe deserialization — Apache SubmarineCWE-502 9.8AICriticalAI2023-11-20
CVE-2023-26031 Privilege escalation in Apache Hadoop Yarn container-executor binary on Linux systems — Apache HadoopCWE-426 7.8 -2023-11-16
CVE-2023-42781 Apache Airflow: Permission verification bypass allows viewing dagruns of other dags — Apache AirflowCWE-200 4.3 -2023-11-12
CVE-2023-47037 Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access) — Apache AirflowCWE-863 5.4 -2023-11-12
CVE-2023-47248 PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file — PyArrowCWE-502 9.8 -2023-11-09
CVE-2023-39913 Apache UIMA Java SDK Core, Apache UIMA Java SDK CPE, Apache UIMA Java SDK Vinci adapter, Apache UIMA Java SDK tools: Potential untrusted code execution when deserializing certain binary CAS formats — Apache UIMA Java SDK CoreCWE-502 9.8 -2023-11-08
CVE-2023-46819 Apache OFBiz: Execution of Solr plugin queries without authentication — Apache OFBizCWE-306 9.8 -2023-11-07
CVE-2023-46851 Apache Allura: sensitive information exposure via import — Apache AlluraCWE-20 9.8 -2023-11-07
CVE-2023-46215 Apache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend — Apache Airflow Celery providerCWE-532 7.5 -2023-10-28
CVE-2023-46604 Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack — Apache ActiveMQCWE-502 10.0 Critical2023-10-27
CVE-2023-46288 Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set — Apache AirflowCWE-200 4.3 -2023-10-23
CVE-2023-31122 Apache HTTP Server: mod_macro buffer over-read — Apache HTTP ServerCWE-125 7.5 -2023-10-23
CVE-2023-43622 Apache HTTP Server: DoS in HTTP/2 with initial windows size 0 — Apache HTTP ServerCWE-400 7.5 -2023-10-23
CVE-2023-45802 Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST — Apache HTTP ServerCWE-404 5.9 -2023-10-23
CVE-2023-44483 Apache Santuario: Private Key disclosure in debug-log output — Apache SantuarioCWE-532 7.5 -2023-10-20
CVE-2023-46227 Apache inlong has an Arbitrary File Read Vulnerability — Apache InLongCWE-502 9.8 -2023-10-19
CVE-2023-25753 Server-Side Request Forgery in Apache ShenYu — Apache ShenYuCWE-918 9.1 -2023-10-19
CVE-2023-39456 Apache Traffic Server: Malformed http/2 frames can cause an abort — Apache Traffic ServerCWE-20 7.5 -2023-10-17
CVE-2023-41752 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic ServerCWE-200 7.5 -2023-10-17
CVE-2023-43666 Apache InLong: General user Unauthorized access User Management — Apache InLongCWE-345 6.5 -2023-10-16
CVE-2023-43667 Apache InLong: Log Injection in Global functions — Apache InLongCWE-74 5.3 -2023-10-16
CVE-2023-43668 Apache InLong: Jdbc Connection Security Bypass in InLong — Apache InLongCWE-639 9.8 -2023-10-16
CVE-2023-45757 Apache bRPC: The builtin service rpcz page has an XSS attack vulnerability — Apache bRPCCWE-79 6.1 -2023-10-16
CVE-2023-42663 Apache Airflow: Bypass permission verification to view task instances of other dags — Apache AirflowCWE-200 4.3 -2023-10-14
CVE-2023-42792 Apache Airflow: Improper access control to DAG resources — Apache AirflowCWE-668 4.3 -2023-10-14
CVE-2023-45348 Apache Airflow: Configuration information leakage vulnerability — Apache AirflowCWE-200 4.3 -2023-10-14

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.