Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-45757 Apache bRPC: The builtin service rpcz page has an XSS attack vulnerability — Apache bRPC CWE-79 6.1 - 2023-10-16
CVE-2023-42663 Apache Airflow: Bypass permission verification to view task instances of other dags — Apache Airflow CWE-200 4.3 - 2023-10-14
CVE-2023-42792 Apache Airflow: Improper access control to DAG resources — Apache Airflow CWE-668 4.3 - 2023-10-14
CVE-2023-45348 Apache Airflow: Configuration information leakage vulnerability — Apache Airflow CWE-200 4.3 - 2023-10-14
CVE-2023-42780 Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature — Apache Airflow CWE-200 4.3 - 2023-10-14
CVE-2023-44981 Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication — Apache ZooKeeper CWE-639 9.1 - 2023-10-11
CVE-2023-45648 Apache Tomcat: Trailer header parsing too lenient — Apache Tomcat CWE-20 7.5 - 2023-10-10
CVE-2023-42795 Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests — Apache Tomcat CWE-459 5.3 - 2023-10-10
CVE-2023-42794 Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows — Apache Tomcat CWE-459 7.5 - 2023-10-10
CVE-2023-39410 Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK — Apache Avro Java SDK CWE-502 7.5 - 2023-09-29
CVE-2023-41834 Apache Flink Stateful Functions allowed HTTP header injection due to Improper Neutralization of CRLF Sequences — Apache Flink Stateful Functions CWE-113 5.4 - 2023-09-19
CVE-2023-41267 Apache HDFS Provider error message suggested installation of incorrect pip package — Apache Airflow HDFS Provider CWE-829 8.8 - 2023-09-14
CVE-2023-42503 Apache Commons Compress: Denial of service via CPU consumption for malformed TAR file — Apache Commons Compress CWE-20 7.5 - 2023-09-14
CVE-2023-41081 Apache Tomcat Connectors: Unexpected use of first declared worker in mod_jk for unmapped request — Apache Tomcat Connectors 6.5 - 2023-09-13
CVE-2023-40712 Apache Airflow: Secrets can be unmasked in the "Rendered Template" — Apache Airflow CWE-200 4.3 - 2023-09-12
CVE-2023-40611 Apache Airflow Dag Runs Broken Access Control Vulnerability — Apache Airflow CWE-863 7.1 - 2023-09-12
CVE-2023-32672 Apache Superset: SQL parser edge case bypasses data access authorization — Apache Superset CWE-863 4.3 Medium 2023-09-06
CVE-2023-37941 Apache Superset: Metadata db write access can lead to remote code execution — Apache Superset CWE-502 6.6 Medium 2023-09-06
CVE-2023-39265 Apache Superset: Possible Unauthorized Registration of SQLite Database Connections — Apache Superset CWE-20 3.8 Low 2023-09-06
CVE-2023-39264 Apache Superset: Stack traces enabled by default — Apache Superset CWE-209 4.3 Medium 2023-09-06
CVE-2023-27523 Apache Superset: Improper data permission validation on Jinja templated queries — Apache Superset CWE-863 5.0 Medium 2023-09-06
CVE-2023-36388 Apache Superset: Improper API permission for low privilege users allows for SSRF — Apache Superset CWE-918 4.3 Medium 2023-09-06
CVE-2023-27526 Apache Superset: Improper Authorization check on import charts — Apache Superset CWE-863 4.3 Medium 2023-09-06
CVE-2023-36387 Apache Superset: Improper API permission for low privilege users — Apache Superset CWE-863 5.4 Medium 2023-09-06
CVE-2023-40743 Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService — Apache Axis CWE-20 9.8 - 2023-09-05
CVE-2023-41180 Apache NiFi MiNiFi C++: Incorrect Certificate Validation in InvokeHTTP for MiNiFi C++ — Apache NiFi MiNiFi C++ CWE-295 5.9 - 2023-09-03
CVE-2023-40195 Apache Airflow Spark Provider Deserialization Vulnerability RCE — Apache Airflow Spark Provider CWE-502 8.0 - 2023-08-28
CVE-2023-27604 Apache Airflow Sqoop Provider: Airflow Sqoop Provider RCE Vulnerability — Apache Airflow Sqoop Provider CWE-20 8.8 - 2023-08-28
CVE-2023-41080 Apache Tomcat: Open redirect with FORM authentication — Apache Tomcat CWE-601 6.1 - 2023-08-25
CVE-2023-39441 Apache Airflow SMTP Provider, Apache Airflow IMAP Provider, Apache Airflow: SMTP/IMAP client components allowed MITM due to missing Certificate Validation — Apache Airflow SMTP Provider CWE-295 6.8 - 2023-08-23

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.