Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-33246 Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function — Apache RocketMQ CWE-94 9.8 - 2023-05-24
CVE-2023-31062 Apache InLong: Privilege escalation vulnerability for InLong — Apache InLong CWE-269 8.8 - 2023-05-22
CVE-2023-31064 Apache InLong: Insecurity direct object references cancelling applications — Apache InLong CWE-552 6.5 - 2023-05-22
CVE-2023-31065 Apache InLong: Insufficient Session Expiration in InLong — Apache InLong CWE-613 9.8 - 2023-05-22
CVE-2023-31066 Apache InLong: Insecure direct object references for inlong sources — Apache InLong CWE-552 8.1 - 2023-05-22
CVE-2023-31098 Apache InLong: Weak Password Implementation in InLong — Apache InLong CWE-521 7.4 - 2023-05-22
CVE-2023-31101 Apache InLong: Users who joined later can see the data of deleted users — Apache InLong CWE-1188 5.3 - 2023-05-22
CVE-2023-31103 Apache InLong: Attackers can change the immutable name and type of cluster — Apache InLong CWE-668 8.2 - 2023-05-22
CVE-2023-31206 Apache InLong: Attackers can change the immutable name and type of nodes — Apache InLong CWE-668 8.2 - 2023-05-22
CVE-2023-31453 Apache InLong: IDOR make users can delete others' subscription — Apache InLong CWE-732 7.5 - 2023-05-22
CVE-2023-31454 Apache InLong: IDOR make users can bind any cluster — Apache InLong CWE-732 9.8 - 2023-05-22
CVE-2023-31058 Apache InLong: JDBC URL bypassing by adding blanks — Apache InLong CWE-502 9.8 - 2023-05-22
CVE-2023-28709 Apache Tomcat: Fix for CVE-2023-24998 is incomplete — Apache Tomcat CWE-193 7.5 - 2023-05-22
CVE-2022-47937 Multiple parsing problems in the Apache Sling Commons JSON module — org.apache.sling.commons.json CWE-20 9.1 - 2023-05-15
CVE-2023-28936 Apache OpenMeetings: insufficient check of invitation hash — Apache OpenMeetings CWE-697 7.5 - 2023-05-12
CVE-2023-29032 Apache OpenMeetings: allows bypass authentication — Apache OpenMeetings CWE-287 8.8 - 2023-05-12
CVE-2023-29246 Apache OpenMeetings: allows null-byte Injection — Apache OpenMeetings CWE-20 7.2 - 2023-05-12
CVE-2023-25754 Apache Airflow: Privilege escalation using airflow logs — Apache Airflow CWE-270 7.5 - 2023-05-08
CVE-2023-29247 Stored XSS on Apache Airflow — Apache Airflow CWE-79 6.1 - 2023-05-08
CVE-2023-31039 Apache bRPC: ServerOptions.pid_file may cause arbitrary code execution — Apache bRPC CWE-20 9.8 - 2023-05-08
CVE-2023-31038 Apache Log4cxx: SQL injection when using ODBC appender — Apache Log4cxx CWE-89 7.2 - 2023-05-08
CVE-2021-40331 Permissions problem in the Apache Ranger Hive Plugin — Apache Ranger Hive Plugin CWE-732 6.5 - 2023-05-05
CVE-2022-45048 Apache Ranger: code execution vulnerability in policy expressions — Apache Ranger CWE-74 8.4 High 2023-05-05
CVE-2023-26268 Apache CouchDB, IBM Cloudant: Information sharing via couchjs processes — Apache CouchDB CWE-200 4.4 Medium 2023-05-02
CVE-2023-32007 Apache Spark: Shell command injection via Spark UI — Apache Spark CWE-77 8.8 - 2023-05-02
CVE-2022-46365 Apache StreamPark (incubating): Logic error causing any account reset — Apache StreamPark (incubating) CWE-20 8.1 - 2023-05-01
CVE-2022-45801 Apache StreamPark (incubating): LDAP Injection Vulnerability — Apache StreamPark (incubating) CWE-74 9.1 - 2023-05-01
CVE-2022-45802 Apache StreamPark (incubating): Upload any file to any directory — Apache StreamPark (incubating) CWE-434 8.1 - 2023-05-01
CVE-2023-22665 Apache Jena: Exposure of arbitrary execution in script engine expressions. — Apache Jena CWE-917 6.1 - 2023-04-25
CVE-2023-30776 Apache Superset: Database connection password leak — Apache Superset CWE-522 4.9 Medium 2023-04-24

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.