Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-37379 Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" feature — Apache Airflow CWE-400 8.1 - 2023-08-23
CVE-2023-40273 Session fixation in Apache Airflow web interface — Apache Airflow CWE-384 8.8 - 2023-08-23
CVE-2022-44729 Apache XML Graphics Batik: Information disclosure vulnerability — Apache XML Graphics Batik CWE-918 8.2 - 2023-08-22
CVE-2022-44730 Apache XML Graphics Batik: Information disclosure vulnerability — Apache XML Graphics Batik CWE-918 6.5 - 2023-08-22
CVE-2022-46751 Apache Ivy: XML External Entity vulnerability in Apache Ivy — Apache Ivy CWE-611 8.6 - 2023-08-21
CVE-2023-40037 Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs — Apache NiFi CWE-184 8.1 - 2023-08-18
CVE-2023-40272 Apache Airflow Spark Provider Arbitrary File Read via JDBC — Apache Airflow Spark Provider CWE-20 7.5 - 2023-08-17
CVE-2023-39553 Apache Airflow Drill Provider Arbitrary File Read Vulnerability — Apache Airflow Drill Provider CWE-20 7.5 - 2023-08-11
CVE-2023-33934 Apache Traffic Server: Differential fuzzing for HTTP request parsing discrepancies — Apache Traffic Server CWE-444 8.2 - 2023-08-09
CVE-2022-47185 Apache Traffic Server: Invalid Range header causes a crash — Apache Traffic Server CWE-20 8.2 - 2023-08-09
CVE-2023-37581 Apache Roller: Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross Site Scripting (XSS) even on a Roller site configured for untrusted users. — Apache Roller CWE-79 5.4 - 2023-08-06
CVE-2023-39508 Apache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledges — Apache Airflow CWE-250 8.8 - 2023-08-05
CVE-2023-36542 Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources — Apache NiFi CWE-94 8.8 - 2023-07-29
CVE-2023-38647 Apache Helix: Deserialization vulnerability in Helix workflow and REST — Apache Helix CWE-502 9.8 - 2023-07-26
CVE-2023-38435 Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole plugin — Apache Felix Healthcheck Webconsole Plugin CWE-79 6.1 - 2023-07-25
CVE-2023-37895 Apache Jackrabbit RMI access can lead to RCE — Apache Jackrabbit Webapp (jackrabbit-webapp) CWE-502 9.8 - 2023-07-25
CVE-2023-35088 Apache InLong: SQL injection in audit endpoint — Apache InLong CWE-89 9.8 - 2023-07-25
CVE-2023-34434 Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param — Apache InLong CWE-502 7.5 - 2023-07-25
CVE-2023-34189 Apache InLong: General user can delete and update process — Apache InLong CWE-668 9.1 - 2023-07-25
CVE-2023-34478 Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests. — Apache Shiro CWE-22 9.8 - 2023-07-24
CVE-2023-28754 ShardingSphere-Agent: Deserialization vulnerability in ShardingSphere Agent — ShardingSphere-Agent CWE-502 7.8 - 2023-07-19
CVE-2023-26512 Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data — Apache EventMesh (incubating) RabbitMQ connector CWE-502 9.8 - 2023-07-17
CVE-2023-37415 Apache Airflow Apache Hive Provider: Improper Input Validation in Hive Provider with proxy_user — Apache Airflow Apache Hive Provider CWE-20 7.1 - 2023-07-13
CVE-2022-45855 Apache Ambari: Allows authenticated metrics consumers to perform RCE — Apache Ambari CWE-917 8.0 High 2023-07-12
CVE-2022-42009 Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application. — Apache Ambari CWE-917 8.0 High 2023-07-12
CVE-2023-37582 Apache RocketMQ: Possible remote code execution when using the update configuration function — Apache RocketMQ CWE-94 9.8 - 2023-07-12
CVE-2023-22888 Apache Airflow: Scheduler remote DoS — Apache Airflow CWE-20 6.5 - 2023-07-12
CVE-2023-36543 Apache Airflow: ReDoS via dags function — Apache Airflow CWE-1333 6.5 - 2023-07-12
CVE-2022-46651 Apache Airflow: Security vulnerability on AirFlow Connections — Apache Airflow CWE-200 6.5 - 2023-07-12
CVE-2023-22887 Apache Airflow path traversal by authenticated user — Apache Airflow CWE-22 6.5 - 2023-07-12

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.