Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-35908 Apache Airflow: Access to DAGs without relevant permission — Apache Airflow CWE-863 5.3 - 2023-07-12
CVE-2023-30428 Apache Pulsar Broker: Incorrect Authorization Validation for Rest Producer — Apache Pulsar Broker CWE-863 8.2 High 2023-07-12
CVE-2023-30429 Apache Pulsar: Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy — Apache Pulsar CWE-863 9.6 Critical 2023-07-12
CVE-2023-31007 Apache Pulsar: Broker does not always disconnect client when authentication data expires — Apache Pulsar CWE-287 - - 2023-07-12
CVE-2023-37579 Apache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials — Apache Pulsar Function Worker CWE-863 8.2 High 2023-07-12
CVE-2023-32200 Apache Jena: Exposure of execution in script engine expressions. — Apache Jena CWE-917 4.6 - 2023-07-12
CVE-2023-34442 Apache Camel JIRA: Temporary file information disclosure in Camel-Jira — Apache Camel JIRA CWE-200 7.5 - 2023-07-10
CVE-2023-35887 Apache MINA SSHD: Information disclosure bugs with RootedFilesystem — Apache MINA SSHD CWE-22 5.0 Medium 2023-07-10
CVE-2023-33008 Apache Johnzon: Prevent inefficient internal conversion from BigDecimal at large scale — Apache Johnzon CWE-502 7.5 - 2023-07-07
CVE-2023-34150 Apache Any23: Possible excessive allocation of resources reading input. — Apache Any23 CWE-20 6.5 Medium 2023-07-05
CVE-2023-35797 Apache Airflow Hive Provider Beeline RCE with Principal — Apache Airflow Apache Hive Provider CWE-20 9.8 - 2023-07-03
CVE-2023-22886 Apache Airflow JDBC Provider: RCE Vulnerability — Apache Airflow JDBC Provider CWE-20 9.8 - 2023-06-29
CVE-2023-35798 Airflow Apache ODBC and MSSQL Providers Arbitrary File Read Vulnerability — Apache Airflow ODBC Provider CWE-20 8.8 - 2023-06-27
CVE-2023-34395 Apache Airflow ODBC Provider: Remote code execution vulnerability — Apache Airflow ODBC Provider CWE-88 9.8 - 2023-06-27
CVE-2023-31469 Apache StreamPipes: Privilege escalation through non-admin user — Apache StreamPipes CWE-269 8.8 - 2023-06-23
CVE-2023-34981 Apache Tomcat: AJP response header mix-up — Apache Tomcat 7.5 - 2023-06-21
CVE-2023-34340 Apache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentials — Apache Accumulo CWE-287 9.1 - 2023-06-21
CVE-2023-35005 Apache Airflow: Information disclosure on configuration view — Apache Airflow CWE-200 7.5 - 2023-06-19
CVE-2023-34396 Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms — Apache Struts CWE-770 4.3 Medium 2023-06-14
CVE-2023-34149 Apache Struts: DoS via OOM owing to not properly checking of list bounds — Apache Struts CWE-770 4.3 Medium 2023-06-14
CVE-2023-30631 Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work — Apache Traffic Server CWE-20 7.5 - 2023-06-14
CVE-2023-33933 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic Server CWE-200 7.5 - 2023-06-14
CVE-2022-47184 Apache Traffic Server: The TRACE method can be use to disclose network information — Apache Traffic Server CWE-200 7.5 - 2023-06-14
CVE-2023-34212 Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components — Apache NiFi CWE-502 8.8 - 2023-06-12
CVE-2023-34468 Apache NiFi: Potential Code Injection with Database Services using H2 — Apache NiFi CWE-94 8.8 - 2023-06-12
CVE-2023-30576 Apache Guacamole: Use-after-free in handling of RDP audio input buffer — Apache Guacamole CWE-416 6.8 Medium 2023-06-07
CVE-2023-30575 Apache Guacamole: Incorrect calculation of Guacamole protocol element lengths — Apache Guacamole CWE-131 6.5 Medium 2023-06-07
CVE-2023-33234 Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration — Apache Airflow CNCF Kubernetes Provider CWE-74 4.9 - 2023-05-30
CVE-2023-30601 Apache Cassandra: Privilege escalation when enabling FQL/Audit logs — Apache Cassandra CWE-269 7.8 High 2023-05-30
CVE-2022-46907 Apache JSPWiki: XSS Injection points in several plugins — Apache JSPWiki CWE-79 6.1 - 2023-05-25

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.