Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-25695 Information disclosure in Apache Airflow — Apache Airflow CWE-209 5.3 - 2023-03-15
CVE-2023-26464 Apache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppender — Apache Log4j CWE-502 7.5 - 2023-03-10
CVE-2023-23638 Apache Dubbo Deserialization Vulnerability Gadgets Bypass — Apache Dubbo CWE-502 5.0 Medium 2023-03-08
CVE-2023-27522 Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting — Apache HTTP Server CWE-444 5.3 - 2023-03-07
CVE-2023-25690 Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy — Apache HTTP Server CWE-444 6.5 - 2023-03-07
CVE-2023-25956 Apache Airflow AWS Provider: Arbitrary file read via AWS provider — Apache Airflow AWS Provider CWE-209 5.3 - 2023-02-24
CVE-2023-25696 Apache Airflow Hive Provider Beeline RCE — Apache Airflow Hive Provider CWE-20 7.5 - 2023-02-24
CVE-2023-25693 Sqoop Apache Airflow Provider Remote Code Execution Vulnerability — Apache Airflow Sqoop Provider CWE-20 9.1 - 2023-02-24
CVE-2023-25692 Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service — Apache Airflow Google Provider CWE-20 9.1 - 2023-02-24
CVE-2023-25691 Apache Airflow Google Provider: Google Cloud Sql Provider Remote Command Execution — Apache Airflow Google Provider CWE-20 9.1 - 2023-02-24
CVE-2023-25621 Apache Sling does not allow to handle i18n content in a secure way — Apache Sling 6.5 - 2023-02-23
CVE-2023-24998 Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts — Apache Commons FileUpload CWE-770 7.5 - 2023-02-20
CVE-2023-25613 LDAP Injection Vulnerability in Apache Kerby — Apache Kerby LDAP Backend CWE-74 9.8 - 2023-02-20
CVE-2022-42735 Apache ShenYu Admin ultra vires — Apache ShenYu CWE-269 8.8 - 2023-02-15
CVE-2023-25141 JNDI injection into Apache sling-org-apache-sling-jcr-base — Apache Sling JCR Base CWE-74 9.1 - 2023-02-14
CVE-2023-22832 Apache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributes — Apache NiFi CWE-611 7.5 - 2023-02-10
CVE-2023-25194 Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect — Apache Kafka Connect API CWE-502 8.8 - 2023-02-07
CVE-2022-45786 Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection — Apache AGE CWE-89 7.5 - 2023-02-04
CVE-2023-22849 Apache Sling App CMS: XSS in CMS Reference / UI Components — Apache Sling App CMS CWE-79 5.4 - 2023-02-04
CVE-2023-24997 Apache InLong: Jdbc Connection Security Bypass — Apache InLong CWE-502 9.8 - 2023-02-01
CVE-2023-24977 Apache InLong: Jdbc Connection causes arbitrary file reading in InLong — Apache InLong CWE-125 7.5 - 2023-02-01
CVE-2022-28331 Apache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv function — Apache Portable Runtime (APR) CWE-190 9.8 - 2023-01-31
CVE-2022-25147 Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functions — Apache Portable Runtime Utility (APR-util) CWE-190 9.8 - 2023-01-31
CVE-2022-24963 Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions — Apache Portable Runtime (APR) CWE-190 9.8 - 2023-01-31
CVE-2022-44644 Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability — Apache Linkis (incubating) CWE-20 6.5 - 2023-01-31
CVE-2022-44645 Apache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerability — Apache Linkis (incubating) CWE-502 8.8 - 2023-01-31
CVE-2023-24829 Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench — Apache IoTDB Workbench CWE-863 8.8 - 2023-01-31
CVE-2023-24830 Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization — Apache IoTDB Workbench CWE-287 9.8 - 2023-01-30
CVE-2023-22884 Apache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache Airflow — Apache Airflow CWE-77 9.8 - 2023-01-21
CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting — Apache HTTP Server CWE-113 7.5 - 2023-01-17

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.