Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2025-23184 Apache CXF: Denial of Service vulnerability with temporary files — Apache CXF CWE-400 5.9 Medium 2025-01-21
CVE-2024-45627 Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability — Apache Linkis Metadata Query Service JDBC CWE-552 6.5 - 2025-01-14
CVE-2025-22828 Apache CloudStack: Unauthorised access to annotations — Apache CloudStack CWE-200 4.2 - 2025-01-13
CVE-2024-45033 Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli — Apache Airflow Fab Provider CWE-613 8.8 - 2025-01-08
CVE-2024-54676 Apache OpenMeetings: Deserialisation of untrusted data in cluster mode — Apache OpenMeetings CWE-502 9.8 - 2025-01-08
CVE-2024-56512 Apache NiFi: Missing Complete Authorization for Parameter and Service References — Apache NiFi CWE-638 6.5 - 2024-12-28
CVE-2024-52046 Apache MINA: MINA applications using unbounded deserialization may allow RCE — Apache MINA CWE-502 9.8 - 2024-12-25
CVE-2024-43441 Apache HugeGraph-Server: Fixed JWT Token(Secret) — Apache HugeGraph-Server CWE-302 9.8 - 2024-12-24
CVE-2024-45387 Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments — Apache Traffic Control CWE-89 9.9 Critical 2024-12-23
CVE-2024-23945 Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails — Apache Hive CWE-209 8.2 - 2024-12-23
CVE-2024-56337 Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete — Apache Tomcat CWE-367 8.1 - 2024-12-20
CVE-2024-56128 Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption — Apache Kafka CWE-303 7.5 - 2024-12-18
CVE-2024-54677 Apache Tomcat: DoS in examples web application — Apache Tomcat CWE-400 7.5 - 2024-12-17
CVE-2024-50379 Apache Tomcat: RCE due to TOCTOU issue in JSP compilation — Apache Tomcat CWE-367 8.1 - 2024-12-17
CVE-2024-55633 Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access — Apache Superset CWE-863 8.8 - 2024-12-12
CVE-2024-53677 Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks — Apache Struts 9.8 - 2024-12-11
CVE-2024-53949 Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled — Apache Superset CWE-863 8.8 - 2024-12-09
CVE-2024-53948 Apache Superset: Error verbosity exposes metadata in analytics databases — Apache Superset CWE-209 5.3 - 2024-12-09
CVE-2024-53947 Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions — Apache Superset CWE-89 9.8 - 2024-12-09
CVE-2024-46901 Apache Subversion: mod_dav_svn denial-of-service via control characters in paths — Apache Subversion CWE-20 3.1 Low 2024-12-09
CVE-2022-41137 Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore — Apache Hive CWE-502 8.8 - 2024-12-05
CVE-2024-45106 Apache Ozone: Improper authentication when generating S3 secrets — Apache Ozone CWE-287 6.8 - 2024-12-03
CVE-2024-52338 Apache Arrow R package: Arbitrary code execution when loading a malicious data file — Apache Arrow R package CWE-502 9.8AI Critical AI 2024-11-28
CVE-2024-51569 Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler — Apache NimBLE CWE-125 7.1AI High AI 2024-11-26
CVE-2024-47250 Apache NimBLE: Lack of input validation in HCI advertising report could lead to potential out-of-bound access — Apache NimBLE CWE-125 7.5AI High AI 2024-11-26
CVE-2024-47249 Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler — Apache NimBLE CWE-129 6.5AI Medium AI 2024-11-26
CVE-2024-47248 Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack — Apache NimBLE CWE-120 9.8AI Critical AI 2024-11-26
CVE-2024-45719 Apache Answer: Predictable Authorization Token Using UUIDv1 — Apache Answer CWE-326 7.5 - 2024-11-22
CVE-2024-52067 Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log — Apache NiFi CWE-532 4.9AI Medium AI 2024-11-21
CVE-2024-31141 Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider — Apache Kafka Clients CWE-552 6.5AI Medium AI 2024-11-19

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.