Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-43701 Apache Superset: Stored XSS on API endpoint — Apache Superset CWE-79 4.3 Medium 2023-11-27
CVE-2023-42501 Apache Superset: Unnecessary read permissions within the Gamma role — Apache Superset CWE-276 4.3 Medium 2023-11-27
CVE-2023-40610 Apache Superset: Privilege escalation with default examples database — Apache Superset CWE-863 6.3 Medium 2023-11-27
CVE-2023-49068 Apache DolphinScheduler: Information Leakage Vulnerability — Apache DolphinScheduler CWE-200 7.5 - 2023-11-27
CVE-2023-48796 Apache dolphinscheduler sensitive information disclosure — Apache DolphinScheduler CWE-200 7.5 - 2023-11-24
CVE-2023-43123 Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files — Apache Storm CWE-200 5.5 - 2023-11-23
CVE-2023-37924 Apache Submarine: SQL injection from unauthorized login — Apache Submarine CWE-89 8.8AI High AI 2023-11-22
CVE-2022-46337 Apache Derby: LDAP injection vulnerability in authenticator — Apache Derby 9.8AI Critical AI 2023-11-20
CVE-2023-46302 Apache Submarine: Fix CVE-2022-1471 SnakeYaml unsafe deserialization — Apache Submarine CWE-502 9.8AI Critical AI 2023-11-20
CVE-2023-26031 Privilege escalation in Apache Hadoop Yarn container-executor binary on Linux systems — Apache Hadoop CWE-426 7.8 - 2023-11-16
CVE-2023-42781 Apache Airflow: Permission verification bypass allows viewing dagruns of other dags — Apache Airflow CWE-200 4.3 - 2023-11-12
CVE-2023-47037 Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access) — Apache Airflow CWE-863 5.4 - 2023-11-12
CVE-2023-47248 PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file — PyArrow CWE-502 9.8 - 2023-11-09
CVE-2023-39913 Apache UIMA Java SDK Core, Apache UIMA Java SDK CPE, Apache UIMA Java SDK Vinci adapter, Apache UIMA Java SDK tools: Potential untrusted code execution when deserializing certain binary CAS formats — Apache UIMA Java SDK Core CWE-502 9.8 - 2023-11-08
CVE-2023-46819 Apache OFBiz: Execution of Solr plugin queries without authentication — Apache OFBiz CWE-306 9.8 - 2023-11-07
CVE-2023-46851 Apache Allura: sensitive information exposure via import — Apache Allura CWE-20 9.8 - 2023-11-07
CVE-2023-46215 Apache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend — Apache Airflow Celery provider CWE-532 7.5 - 2023-10-28
CVE-2023-46604 Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack — Apache ActiveMQ CWE-502 10.0 Critical 2023-10-27
CVE-2023-46288 Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set — Apache Airflow CWE-200 4.3 - 2023-10-23
CVE-2023-31122 Apache HTTP Server: mod_macro buffer over-read — Apache HTTP Server CWE-125 7.5 - 2023-10-23
CVE-2023-43622 Apache HTTP Server: DoS in HTTP/2 with initial windows size 0 — Apache HTTP Server CWE-400 7.5 - 2023-10-23
CVE-2023-45802 Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST — Apache HTTP Server CWE-404 5.9 - 2023-10-23
CVE-2023-44483 Apache Santuario: Private Key disclosure in debug-log output — Apache Santuario CWE-532 7.5 - 2023-10-20
CVE-2023-46227 Apache inlong has an Arbitrary File Read Vulnerability — Apache InLong CWE-502 9.8 - 2023-10-19
CVE-2023-25753 Server-Side Request Forgery in Apache ShenYu — Apache ShenYu CWE-918 9.1 - 2023-10-19
CVE-2023-39456 Apache Traffic Server: Malformed http/2 frames can cause an abort — Apache Traffic Server CWE-20 7.5 - 2023-10-17
CVE-2023-41752 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic Server CWE-200 7.5 - 2023-10-17
CVE-2023-43666 Apache InLong: General user Unauthorized access User Management — Apache InLong CWE-345 6.5 - 2023-10-16
CVE-2023-43667 Apache InLong: Log Injection in Global functions — Apache InLong CWE-74 5.3 - 2023-10-16
CVE-2023-43668 Apache InLong: Jdbc Connection Security Bypass in InLong — Apache InLong CWE-639 9.8 - 2023-10-16

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.