Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1676

Browse all 1676 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-37579 Apache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials — Apache Pulsar Function WorkerCWE-863 8.2 High2023-07-12
CVE-2023-32200 Apache Jena: Exposure of execution in script engine expressions. — Apache JenaCWE-917 4.6 -2023-07-12
CVE-2023-34442 Apache Camel JIRA: Temporary file information disclosure in Camel-Jira — Apache Camel JIRACWE-200 7.5 -2023-07-10
CVE-2023-35887 Apache MINA SSHD: Information disclosure bugs with RootedFilesystem — Apache MINA SSHDCWE-22 5.0 Medium2023-07-10
CVE-2023-33008 Apache Johnzon: Prevent inefficient internal conversion from BigDecimal at large scale — Apache JohnzonCWE-502 7.5 -2023-07-07
CVE-2023-34150 Apache Any23: Possible excessive allocation of resources reading input. — Apache Any23CWE-20 6.5 Medium2023-07-05
CVE-2023-35797 Apache Airflow Hive Provider Beeline RCE with Principal — Apache Airflow Apache Hive ProviderCWE-20 9.8 -2023-07-03
CVE-2023-22886 Apache Airflow JDBC Provider: RCE Vulnerability — Apache Airflow JDBC ProviderCWE-20 9.8 -2023-06-29
CVE-2023-35798 Airflow Apache ODBC and MSSQL Providers Arbitrary File Read Vulnerability — Apache Airflow ODBC ProviderCWE-20 8.8 -2023-06-27
CVE-2023-34395 Apache Airflow ODBC Provider: Remote code execution vulnerability — Apache Airflow ODBC ProviderCWE-88 9.8 -2023-06-27
CVE-2023-31469 Apache StreamPipes: Privilege escalation through non-admin user — Apache StreamPipesCWE-269 8.8 -2023-06-23
CVE-2023-34981 Apache Tomcat: AJP response header mix-up — Apache Tomcat 7.5 -2023-06-21
CVE-2023-34340 Apache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentials — Apache AccumuloCWE-287 9.1 -2023-06-21
CVE-2023-35005 Apache Airflow: Information disclosure on configuration view — Apache AirflowCWE-200 7.5 -2023-06-19
CVE-2023-34396 Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms — Apache StrutsCWE-770 4.3 Medium2023-06-14
CVE-2023-34149 Apache Struts: DoS via OOM owing to not properly checking of list bounds — Apache StrutsCWE-770 4.3 Medium2023-06-14
CVE-2023-30631 Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work — Apache Traffic ServerCWE-20 7.5 -2023-06-14
CVE-2023-33933 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic ServerCWE-200 7.5 -2023-06-14
CVE-2022-47184 Apache Traffic Server: The TRACE method can be use to disclose network information — Apache Traffic ServerCWE-200 7.5 -2023-06-14
CVE-2023-34212 Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components — Apache NiFiCWE-502 8.8 -2023-06-12
CVE-2023-34468 Apache NiFi: Potential Code Injection with Database Services using H2 — Apache NiFiCWE-94 8.8 -2023-06-12
CVE-2023-30576 Apache Guacamole: Use-after-free in handling of RDP audio input buffer — Apache GuacamoleCWE-416 6.8 Medium2023-06-07
CVE-2023-30575 Apache Guacamole: Incorrect calculation of Guacamole protocol element lengths — Apache GuacamoleCWE-131 6.5 Medium2023-06-07
CVE-2023-33234 Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration — Apache Airflow CNCF Kubernetes ProviderCWE-74 4.9 -2023-05-30
CVE-2023-30601 Apache Cassandra: Privilege escalation when enabling FQL/Audit logs — Apache CassandraCWE-269 7.8 High2023-05-30
CVE-2022-46907 Apache JSPWiki: XSS Injection points in several plugins — Apache JSPWikiCWE-79 6.1 -2023-05-25
CVE-2023-33246 Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function — Apache RocketMQCWE-94 9.8 -2023-05-24
CVE-2023-31062 Apache InLong: Privilege escalation vulnerability for InLong — Apache InLongCWE-269 8.8 -2023-05-22
CVE-2023-31064 Apache InLong: Insecurity direct object references cancelling applications — Apache InLongCWE-552 6.5 -2023-05-22
CVE-2023-31065 Apache InLong: Insufficient Session Expiration in InLong — Apache InLongCWE-613 9.8 -2023-05-22

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.