Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-27524 Apache Superset: Session validation vulnerability when using provided default SECRET_KEY — Apache Superset CWE-1188 8.9 High 2023-04-24
CVE-2023-25601 Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication — Apache DolphinScheduler CWE-287 9.1 - 2023-04-20
CVE-2023-25504 Apache Superset: Possible SSRF on import datasets — Apache Superset CWE-918 4.9 Medium 2023-04-17
CVE-2023-27525 Apache Superset: Incorrect default permissions for Gamma role — Apache Superset CWE-863 3.1 Low 2023-04-17
CVE-2023-22946 Apache Spark proxy-user privilege escalation from malicious configuration class — Apache Spark CWE-269 6.4 Medium 2023-04-17
CVE-2023-30771 Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench — Apache IoTDB Workbench CWE-863 9.8 - 2023-04-17
CVE-2023-24831 Apache IoTDB grafana-connector Login Bypass Vulnerability — Apache IoTDB CWE-287 8.8 - 2023-04-17
CVE-2022-47501 Apache OFBiz: Arbitrary file reading vulnerability — Apache OFBiz CWE-22 7.5 - 2023-04-14
CVE-2022-45064 Apache Sling Engine: Include-based XSS — Apache Sling Engine CWE-79 8.0 High 2023-04-13
CVE-2023-30465 Apache InLong: SQL injection in apache inLong 1.5.0 — Apache InLong CWE-89 5.3 - 2023-04-11
CVE-2023-29216 Apache Linkis DatasourceManager module has a deserialization command execution — Apache Linkis CWE-502 9.8 - 2023-04-10
CVE-2023-27987 Apache Linkis gateway module token authentication bypass — Apache Linkis CWE-326 9.1 - 2023-04-10
CVE-2023-27603 Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue — Apache Linkis CWE-22 9.8 - 2023-04-10
CVE-2023-27602 Apache Linkis publicsercice module unrestricted upload of file — Apache Linkis CWE-434 9.8 - 2023-04-10
CVE-2023-29215 Apache Linkis JDBC EngineCon has a deserialization command execution — Apache Linkis CWE-502 9.8 - 2023-04-10
CVE-2023-28710 Apache Airflow Spark Provider Arbitrary File Read via JDBC — Apache Airflow Spark Provider CWE-20 - - 2023-04-07
CVE-2023-28706 Apache Airflow Hive Provider Beeline Remote Command Execution — Apache Airflow Hive Provider CWE-94 9.8 - 2023-04-07
CVE-2023-28707 Airflow Apache Drill Provider Arbitrary File Read Vulnerability — Apache Airflow Drill Provider CWE-20 - - 2023-04-07
CVE-2023-26269 Apache James server: Privilege escalation through unauthenticated JMX — Apache James server CWE-862 7.8 - 2023-04-03
CVE-2023-28935 Apache UIMA DUCC: DUCC (EOL) allows RCE — Apache UIMA DUCC CWE-77 8.8 - 2023-03-30
CVE-2023-28158 Apache Archiva privilege escalation — Apache Archiva CWE-79 6.5 Medium 2023-03-29
CVE-2023-28326 Apache OpenMeetings: allows user impersonation — Apache OpenMeetings CWE-306 9.8 - 2023-03-28
CVE-2023-25197 apache fineract: SQL injection vulnerability in certain procedure calls — apache fineract CWE-89 9.8 - 2023-03-28
CVE-2023-25196 Apache Fineract: SQL injection vulnerability — Apache Fineract CWE-89 8.1 - 2023-03-28
CVE-2023-25195 Apache Fineract: SSRF template type vulnerability in certain authenticated users — Apache Fineract CWE-918 8.1 - 2023-03-28
CVE-2023-27296 Apache InLong: JDBC Deserialization Vulnerability in InLong — Apache InLong CWE-502 8.8 - 2023-03-27
CVE-2022-47502 Apache OpenOffice: Macro URL arbitrary script execution — Apache OpenOffice CWE-20 7.3 - 2023-03-24
CVE-2022-38745 Apache OpenOffice: Empty entry in Java class path — Apache OpenOffice CWE-94 9.8 - 2023-03-24
CVE-2023-28708 Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations — Apache Tomcat CWE-523 6.5 - 2023-03-22
CVE-2023-26513 Apache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoS — Apache Sling Resource Merger CWE-834 7.5 High 2023-03-20

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.