Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2024-56736 Apache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config Oss — Apache HertzBeat CWE-918 9.1AI Critical AI 2025-04-16
CVE-2025-24859 Apache Roller: Insufficient Session Expiration on Password Change — Apache Roller CWE-613 8.8AI High AI 2025-04-14
CVE-2025-27391 Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log — Apache ActiveMQ Artemis CWE-532 7.5 - 2025-04-09
CVE-2025-31672 Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names — Apache POI CWE-20 7.5 - 2025-04-09
CVE-2025-30677 Apache Pulsar IO Kafka Connector, Apache Pulsar IO Kafka Connect Adaptor: Sensitive information logged in Pulsar's Apache Kafka Connectors — Apache Pulsar IO Kafka Connector CWE-532 8.1AI High AI 2025-04-09
CVE-2025-30473 Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection — Apache Airflow Common SQL Provider CWE-89 8.8AI High AI 2025-04-07
CVE-2024-53868 Apache Traffic Server: Malformed chunked message body allows request smuggling — Apache Traffic Server CWE-444 7.5AI High AI 2025-04-03
CVE-2025-30676 Apache OFBiz: Stored XSS Vulnerability — Apache OFBiz CWE-80 6.1 - 2025-04-01
CVE-2025-30177 Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering — Apache Camel 7.5 - 2025-04-01
CVE-2024-56325 Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required — Apache Pinot CWE-288 9.8AI Critical AI 2025-04-01
CVE-2025-29868 Apache Answer: Using externally referenced images can leak user privacy. — Apache Answer CWE-495 6.5 - 2025-04-01
CVE-2025-30065 Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata — Apache Parquet Java CWE-502 9.8AI Critical AI 2025-04-01
CVE-2025-27427 Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission — Apache ActiveMQ Artemis CWE-863 6.5 - 2025-04-01
CVE-2025-30067 Apache Kylin: The remote code execution via jdbc url — Apache Kylin CWE-94 9.8AI Critical AI 2025-03-27
CVE-2024-48944 Apache Kylin: SSRF vulnerability in the diagnosis api — Apache Kylin CWE-918 4.4AI Medium AI 2025-03-27
CVE-2024-53679 Apache VCL: XSS vulnerability in User Lookup impacting user privileges — Apache VCL CWE-79 5.4AI Medium AI 2025-03-25
CVE-2024-53678 Apache VCL: SQL injection vulnerability in New Block Allocation form — Apache VCL CWE-89 5.3AI Medium AI 2025-03-25
CVE-2025-27553 Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT — Apache Commons VFS CWE-23 - - 2025-03-23
CVE-2025-30474 Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message — Apache Commons VFS CWE-200 7.5 - 2025-03-23
CVE-2025-26796 Apache Oozie: XSS in Oozie Web Console — Apache Oozie CWE-79 6.1 - 2025-03-22
CVE-2025-27888 Apache Druid: Server-Side Request Forgery and Cross-Site Scripting — Apache Druid CWE-918 5.4 - 2025-03-20
CVE-2024-54016 compression bomb attack in Apache Seata Server — Apache Seata (incubating) CWE-409 9.1 - 2025-03-20
CVE-2024-47552 Apache Seata (incubating): Deserialization of untrusted Data in jraft mode in Apache Seata Server — Apache Seata (incubating) CWE-502 9.8 - 2025-03-20
CVE-2025-27018 Apache Airflow MySQL Provider: SQL injection in MySQL provider core function — Apache Airflow MySQL Provider CWE-89 8.8 - 2025-03-19
CVE-2025-27017 Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record — Apache NiFi CWE-538 6.5 - 2025-03-12
CVE-2025-27867 Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin — Apache Felix HTTP Webconsole Plugin CWE-79 6.1 - 2025-03-12
CVE-2025-29891 Apache Camel: Camel Message Header Injection through request parameters — Apache Camel CWE-164 8.2 - 2025-03-12
CVE-2025-24813 Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT — Apache Tomcat CWE-44 8.8 - 2025-03-10
CVE-2025-26865 Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE — Apache OFBiz CWE-1336 9.8 - 2025-03-10
CVE-2025-27636 Apache Camel: Camel Message Header Injection via Improper Filtering — Apache Camel 7.5 - 2025-03-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.