Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2024-42447 Apache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow — Apache Airflow Providers FAB CWE-613 9.1AI Critical AI 2024-08-05
CVE-2024-36268 Apache InLong TubeMQ Client: Remote Code Execution vulnerability — Apache InLong TubeMQ Client CWE-94 9.8AI Critical AI 2024-08-02
CVE-2024-27182 Apache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerability — Apache Linkis Basic management services CWE-552 6.5AI Medium AI 2024-08-02
CVE-2024-27181 Apache Linkis Basic management services: Privilege Escalation Attack vulnerability — Apache Linkis Basic management services CWE-269 6.5AI Medium AI 2024-08-02
CVE-2023-48396 Apache SeaTunnel Web: Authentication bypass — Apache SeaTunnel Web CWE-290 9.8AI Critical AI 2024-07-30
CVE-2023-38522 Apache Traffic Server: Incomplete field name check allows request smuggling — Apache Traffic Server CWE-444 5.3 - 2024-07-26
CVE-2024-35296 Apache Traffic Server: Invalid Accept-Encoding can force forwarding requests — Apache Traffic Server CWE-20 5.3 - 2024-07-26
CVE-2024-35161 Apache Traffic Server: Incomplete check for chunked trailer section allows request smuggling — Apache Traffic Server CWE-444 5.3 - 2024-07-26
CVE-2024-25090 Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode — Apache Roller CWE-20 5.4 - 2024-07-26
CVE-2023-48362 Apache Drill: XXE Vulnerability in XML Format Reader — Apache Drill CWE-611 8.8AI High AI 2024-07-24
CVE-2024-39676 Apache Pinot: Unauthorized endpoint exposed sensitive information — Apache Pinot CWE-200 5.3AI Medium AI 2024-07-24
CVE-2024-41178 Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files — Apache Arrow Rust Object Store CWE-532 8.1AI High AI 2024-07-23
CVE-2024-29070 Apache StreamPark: session not invalidated after logout — Apache StreamPark CWE-613 6.5AI Medium AI 2024-07-23
CVE-2024-34457 Apache StreamPark IDOR Vulnerability — Apache StreamPark CWE-639 6.5AI Medium AI 2024-07-22
CVE-2024-38503 Apache Syncope: HTML tags can be injected into Console or Enduser text fields — Apache Syncope CWE-79 5.4AI Medium AI 2024-07-22
CVE-2024-23321 Apache RocketMQ: Unauthorized Exposure of Sensitive Data — Apache RocketMQ CWE-200 8.8AI High AI 2024-07-22
CVE-2024-41107 Apache CloudStack: SAML Signature Exclusion — Apache CloudStack CWE-290 9.8 - 2024-07-19
CVE-2024-41172 Apache CXF: Unrestricted memory consumption in CXF HTTP clients — Apache CXF CWE-401 7.5 - 2024-07-19
CVE-2024-32007 Apache CXF Denial of Service vulnerability in JOSE — Apache CXF CWE-400 7.5 - 2024-07-19
CVE-2024-29736 Apache CXF: SSRF vulnerability via WADL stylesheet parameter — Apache CXF CWE-918 9.1 - 2024-07-19
CVE-2024-29178 Apache StreamPark: FreeMarker SSTI RCE Vulnerability — Apache StreamPark CWE-94 8.8AI High AI 2024-07-18
CVE-2024-40725 Apache HTTP Server: source code disclosure with handlers configured via AddType — Apache HTTP Server CWE-668 7.5 - 2024-07-18
CVE-2024-40898 Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows — Apache HTTP Server CWE-918 7.5AI High AI 2024-07-18
CVE-2024-29120 Apache StreamPark: Information leakage vulnerability — Apache StreamPark CWE-212 8.8AI High AI 2024-07-17
CVE-2024-31411 Apache StreamPipes: Potential remote code execution (RCE) via file upload — Apache StreamPipes CWE-434 8.8AI High AI 2024-07-17
CVE-2024-31979 Apache StreamPipes: Possibility of SSRF in pipeline element installation process — Apache StreamPipes CWE-918 8.1AI High AI 2024-07-17
CVE-2024-30471 Apache StreamPipes: Potential creation of multiple identical accounts — Apache StreamPipes CWE-367 7.4AI High AI 2024-07-17
CVE-2024-29737 Apache StreamPark (incubating): maven build params could trigger remote command execution — Apache StreamPark (incubating) CWE-77 8.8AI High AI 2024-07-17
CVE-2023-52291 Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution — Apache StreamPark (incubating) CWE-77 8.8AI High AI 2024-07-17
CVE-2024-39877 Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler — Apache Airflow CWE-94 8.8AI High AI 2024-07-17

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.