Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2022-36760 Apache HTTP Server: mod_proxy_ajp Possible request smuggling — Apache HTTP Server CWE-444 3.7 - 2023-01-17
CVE-2006-20001 Apache HTTP Server: mod_dav out of bounds read, or write of zero byte — Apache HTTP Server CWE-787 7.5 - 2023-01-17
CVE-2022-41703 Apache Superset: SQL injection vulnerability in adhoc clauses — Apache Superset 5.4 - 2023-01-16
CVE-2022-45438 Apache Superset: Dashboard metadata information leak — Apache Superset CWE-668 5.3 - 2023-01-16
CVE-2022-43721 Apache Superset: Open Redirect Vulnerability — Apache Superset CWE-601 5.4 - 2023-01-16
CVE-2022-43720 Apache Superset: Improper rendering of user input — Apache Superset CWE-74 4.6 - 2023-01-16
CVE-2022-43719 Apache Superset: Cross Site Request Forgery (CSRF) on accept, request access API — Apache Superset CWE-352 8.8 - 2023-01-16
CVE-2022-43718 Apache Superset: Cross-Site Scripting vulnerability on upload forms — Apache Superset CWE-79 5.4 - 2023-01-16
CVE-2022-43717 Apache Superset: Cross-Site Scripting on dashboards — Apache Superset CWE-79 5.4 - 2023-01-16
CVE-2023-22602 Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request — Apache Shiro CWE-436 7.5 - 2023-01-14
CVE-2022-46769 Apache Sling App CMS: XSS in CMS Site Group Detail — Apache Sling App CMS CWE-79 5.4 - 2023-01-09
CVE-2022-45935 Apache James server: Temporary File Information Disclosure — Apache James server CWE-668 5.5 - 2023-01-06
CVE-2022-45787 Apache James MIME4J: Temporary File Information Disclosure in MIME4J TempFileStorageProvider — Apache James MIME4J CWE-312 5.5 - 2023-01-06
CVE-2022-45875 Apache DolphinScheduler: Remote command execution Vulnerability in script alert plugin — Apache DolphinScheduler CWE-20 9.8 - 2023-01-04
CVE-2022-45143 Apache Tomcat: JsonErrorReportValve escaping — Apache Tomcat CWE-116 7.5 - 2023-01-03
CVE-2022-44621 Apache Kylin: Command injection by Diagnosis Controller — Apache Kylin 9.8 - 2022-12-30
CVE-2022-43396 Apache Kylin: Command injection by Useless configuration — Apache Kylin 8.8 - 2022-12-30
CVE-2022-45347 Apache ShardingSphere-Proxy: MySQL authentication bypass — Apache ShardingSphere-Proxy CWE-459 9.8 - 2022-12-22
CVE-2022-40145 Apache Karaf: JDBC JAAS LDAP injection — Apache Karaf CWE-74 9.8 - 2022-12-21
CVE-2022-46421 Apache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_params — Apache Airflow Hive Provider CWE-77 9.8 - 2022-12-20
CVE-2022-40743 Apache Traffic Server: Security issues with the xdebug plugin — Apache Traffic Server CWE-79 6.1 - 2022-12-19
CVE-2022-37392 Apache Traffic Server: Improperly reading the client requests — Apache Traffic Server CWE-754 8.2 - 2022-12-19
CVE-2022-32749 Apache Traffic Server: Improperly handled requests can cause crashes in specific plugins — Apache Traffic Server CWE-754 7.5 - 2022-12-19
CVE-2022-47500 Apache Helix: Open redirect — Apache Helix CWE-601 6.1 - 2022-12-19
CVE-2022-46870 Apache Zeppelin: Stored XSS in note permissions — Apache Zeppelin CWE-79 5.4 - 2022-12-16
CVE-2021-28655 Apache Zeppelin: Arbitrary file deletion vulnerability — Apache Zeppelin CWE-20 8.2 - 2022-12-16
CVE-2022-32531 Apache BookKeeper: Java Client Uses Connection to Host that Failed Hostname Verification — Apache BookKeeper CWE-295 5.9 - 2022-12-15
CVE-2022-34271 Apache Atlas: zip path traversal in import functionality — Apache Atlas CWE-22 8.1 - 2022-12-14
CVE-2022-46364 Apache CXF SSRF Vulnerability — Apache CXF CWE-918 9.1 - 2022-12-13
CVE-2022-46363 Apache CXF directory listing / code exfiltration — Apache CXF CWE-20 9.1 - 2022-12-13

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.