Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2345

Browse all 2345 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

Found 145 results / 2345 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-47037 Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access) — Apache Airflow CWE-863 5.4 - 2023-11-12
CVE-2023-46288 Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set — Apache Airflow CWE-200 4.3 - 2023-10-23
CVE-2023-42663 Apache Airflow: Bypass permission verification to view task instances of other dags — Apache Airflow CWE-200 4.3 - 2023-10-14
CVE-2023-42792 Apache Airflow: Improper access control to DAG resources — Apache Airflow CWE-668 4.3 - 2023-10-14
CVE-2023-45348 Apache Airflow: Configuration information leakage vulnerability — Apache Airflow CWE-200 4.3 - 2023-10-14
CVE-2023-42780 Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature — Apache Airflow CWE-200 4.3 - 2023-10-14
CVE-2023-40712 Apache Airflow: Secrets can be unmasked in the "Rendered Template" — Apache Airflow CWE-200 4.3 - 2023-09-12
CVE-2023-40611 Apache Airflow Dag Runs Broken Access Control Vulnerability — Apache Airflow CWE-863 7.1 - 2023-09-12
CVE-2023-37379 Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" feature — Apache Airflow CWE-400 8.1 - 2023-08-23
CVE-2023-40273 Session fixation in Apache Airflow web interface — Apache Airflow CWE-384 8.8 - 2023-08-23
CVE-2023-39508 Apache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledges — Apache Airflow CWE-250 8.8 - 2023-08-05
CVE-2023-22888 Apache Airflow: Scheduler remote DoS — Apache Airflow CWE-20 6.5 - 2023-07-12
CVE-2023-36543 Apache Airflow: ReDoS via dags function — Apache Airflow CWE-1333 6.5 - 2023-07-12
CVE-2022-46651 Apache Airflow: Security vulnerability on AirFlow Connections — Apache Airflow CWE-200 6.5 - 2023-07-12
CVE-2023-22887 Apache Airflow path traversal by authenticated user — Apache Airflow CWE-22 6.5 - 2023-07-12
CVE-2023-35908 Apache Airflow: Access to DAGs without relevant permission — Apache Airflow CWE-863 5.3 - 2023-07-12
CVE-2023-35005 Apache Airflow: Information disclosure on configuration view — Apache Airflow CWE-200 7.5 - 2023-06-19
CVE-2023-25754 Apache Airflow: Privilege escalation using airflow logs — Apache Airflow CWE-270 7.5 - 2023-05-08
CVE-2023-29247 Stored XSS on Apache Airflow — Apache Airflow CWE-79 6.1 - 2023-05-08
CVE-2023-25695 Information disclosure in Apache Airflow — Apache Airflow CWE-209 5.3 - 2023-03-15
CVE-2023-22884 Apache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache Airflow — Apache Airflow CWE-77 9.8 - 2023-01-21
CVE-2022-45402 Apache Airflow: Open redirect during login — Apache Airflow CWE-601 6.1 - 2022-11-15
CVE-2022-27949 Apache Airflow prior to 2.3.1 may include sensitive values in rendered template — Apache Airflow CWE-200 7.5 - 2022-11-14
CVE-2022-40127 Apache Airflow <2.4.0 has an RCE in a bash example — Apache Airflow CWE-94 8.8 - 2022-11-14
CVE-2022-43982 Apache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URL — Apache Airflow CWE-79 6.1 - 2022-11-02
CVE-2022-43985 Apache Airflow prior to 2.4.2 has an open redirect — Apache Airflow CWE-601 6.1 - 2022-11-02
CVE-2022-41672 Session still functional after user is deactivated — Apache Airflow CWE-613 8.1 - 2022-10-07
CVE-2022-40754 Open Redirect — Apache Airflow CWE-601 6.1 - 2022-09-21
CVE-2022-40604 Format String Vulnerability — Apache Airflow CWE-134 7.5 - 2022-09-21
CVE-2022-38054 Session Fixation — Apache Airflow CWE-384 9.8 - 2022-09-02

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.