Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2024-47554 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader — Apache Commons IO CWE-400 7.5 - 2024-10-03
CVE-2024-47561 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro schema (Java SDK) — Apache Avro Java SDK CWE-502 9.8 - 2024-10-03
CVE-2024-45772 Apache Lucene Replicator: Security Vulnerability in Lucene Replicator - Deserialization Issue — Apache Lucene Replicator CWE-502 5.1 Medium 2024-09-30
CVE-2024-47197 Maven Archetype Plugin: Maven Archetype integration-test may package local settings into the published artifact, possibly containing credentials — Maven Archetype Plugin CWE-200 7.5AI High AI 2024-09-26
CVE-2024-23454 Apache Hadoop: Temporary File Local Information Disclosure — Apache Hadoop CWE-378 5.5AI Medium AI 2024-09-25
CVE-2024-40761 Apache Answer: Avatar URL leaked user email addresses — Apache Answer CWE-326 7.5AI High AI 2024-09-25
CVE-2024-39928 Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability — Apache Linkis Spark EngineConn CWE-326 5.3AI Medium AI 2024-09-24
CVE-2024-46544 Apache Tomcat Connectors: mod_jk: local users can view and modify configuration — Apache Tomcat Connectors CWE-276 7.8AI High AI 2024-09-23
CVE-2024-42323 Apache HertzBeat: RCE by snakeYaml deser load malicious xml — Apache HertzBeat CWE-502 8.8 - 2024-09-21
CVE-2024-45537 Apache Druid: Users can provide MySQL JDBC properties not on allow list — Apache Druid CWE-20 6.5 - 2024-09-17
CVE-2024-45384 Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack — Apache Druid 7.5 - 2024-09-17
CVE-2024-22399 Apache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server — Apache Seata CWE-502 9.8 - 2024-09-16
CVE-2024-45034 Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes — Apache Airflow CWE-250 7.8 - 2024-09-07
CVE-2024-45498 Apache Airflow: Command Injection in an example DAG — Apache Airflow CWE-116 8.8 - 2024-09-07
CVE-2024-45195 Apache OFBiz: Confused controller-view authorization logic (forced browsing) — Apache OFBiz CWE-425 9.1AI Critical AI 2024-09-04
CVE-2024-45507 Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE — Apache OFBiz CWE-918 9.8AI Critical AI 2024-09-04
CVE-2023-49582 Apache Portable Runtime (APR): Unexpected lax shared memory permissions — Apache Portable Runtime (APR) CWE-732 3.3AI Low AI 2024-08-26
CVE-2024-41937 Apache Airflow: Stored XSS Vulnerability on provider link — Apache Airflow CWE-79 6.1AI Medium AI 2024-08-21
CVE-2023-49198 Apache SeaTunnel Web: Arbitrary file read vulnerability — Apache SeaTunnel Web CWE-552 7.5AI High AI 2024-08-21
CVE-2024-22281 Apache Helix Front (UI): Helix front hard-coded secret in the express-session — Apache Helix Front (UI) CWE-668 9.1AI Critical AI 2024-08-20
CVE-2024-43202 Apache DolphinScheduler: Remote Code Execution Vulnerability — Apache DolphinScheduler CWE-94 9.8AI Critical AI 2024-08-20
CVE-2024-41909 Apache MINA SSHD: integrity check bypass — Apache MINA SSHD CWE-354 - - AI 2024-08-12
CVE-2024-41888 Apache Answer: The link for resetting user password is not Single-Use — Apache Answer CWE-772 7.5AI High AI 2024-08-09
CVE-2024-41890 Apache Answer: The link to reset the user's password will remain valid after sending a new link — Apache Answer CWE-772 7.5AI High AI 2024-08-09
CVE-2024-30188 Apache DolphinScheduler: Resource File Read And Write Vulnerability — Apache DolphinScheduler CWE-20 8.1AI High AI 2024-08-09
CVE-2024-29831 Apache DolphinScheduler: RCE by arbitrary js execution — Apache DolphinScheduler CWE-20 8.2AI High AI 2024-08-09
CVE-2024-42062 Apache CloudStack: User Key Exposure to Domain Admins — Apache CloudStack CWE-863 7.2AI High AI 2024-08-07
CVE-2024-42222 Apache CloudStack: Unauthorised Network List Access — Apache CloudStack CWE-200 4.3AI Medium AI 2024-08-07
CVE-2024-36448 Apache IoTDB Workbench: SSRF Vulnerability (EOL) — Apache IoTDB Workbench CWE-918 9.8AI Critical AI 2024-08-05
CVE-2024-38856 Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code — Apache OFBiz CWE-863 5.6AI Medium AI 2024-08-05

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.