Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2022-45910 Apache ManifoldCF: LDAP Injection Vulnerability - ActiveDirectory Authorities — Apache ManifoldCF CWE-90 8.2 - 2022-12-07
CVE-2021-37533 Apache Commons Net's FTP client trusts the host from PASV response by default — Apache Commons Net CWE-20 6.5 - 2022-12-03
CVE-2022-46366 Apache Tapestry prior to version 4 (EOL) allows RCE though deserialization of untrusted input — Apache Tapestry CWE-502 9.8 - 2022-12-02
CVE-2022-44635 Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal — Apache Fineract CWE-22 8.8 - 2022-11-29
CVE-2022-26885 Apache DolphinScheduler config file read by task risk — Apache DolphinScheduler 7.5 - 2022-11-24
CVE-2022-45462 Apache DolphinScheduler prior to 2.0.5 have command execution vulnerability — Apache DolphinScheduler CWE-77 9.8 - 2022-11-23
CVE-2022-38649 Apache Airflow Pinot provider allowed Command Injection — Apache Airflow Pinot Provider CWE-78 9.8 - 2022-11-22
CVE-2022-40189 Apache Airlfow Pig Provider RCE — Apache Airlfow Pig Provider CWE-78 9.8 - 2022-11-22
CVE-2022-40954 Apache Airflow Spark Provider RCE that bypass restrictions to read arbitrary files — Apache Airflow Spark Provider CWE-78 5.5 - 2022-11-22
CVE-2022-41131 Apache Airflow Hive Provider vulnerability (command injection via hive_cli connection) — Apache Airflow Hive Provider CWE-78 8.4 - 2022-11-22
CVE-2022-45470 Apache Hama allows XSS and information disclosure — Apache Hama CWE-20 6.5 - 2022-11-21
CVE-2022-45047 Apache MINA SSHD: Java unsafe deserialization vulnerability — Apache MINA SSHD CWE-502 9.8 - 2022-11-16
CVE-2022-40308 Apache Archiva prior to 2.2.9 may allow the anonymous user to read arbitrary files — Apache Archiva 7.5 - 2022-11-15
CVE-2022-40309 Apache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directories — Apache Archiva 4.3 - 2022-11-15
CVE-2022-45402 Apache Airflow: Open redirect during login — Apache Airflow CWE-601 6.1 - 2022-11-15
CVE-2022-27949 Apache Airflow prior to 2.3.1 may include sensitive values in rendered template — Apache Airflow CWE-200 7.5 - 2022-11-14
CVE-2022-40127 Apache Airflow <2.4.0 has an RCE in a bash example — Apache Airflow CWE-94 8.8 - 2022-11-14
CVE-2022-45136 Apache Jena SDB allows arbitrary deserialisation via JDBC — Apache Jena SDB CWE-502 9.8 - 2022-11-14
CVE-2022-45378 Apache SOAP allows unauthenticated users to potentially invoke arbitrary code — Apache SOAP CWE-306 9.8 - 2022-11-14
CVE-2022-37865 Apache Ivy allows creating/overwriting any file on the system — Apache Ivy 9.1 - 2022-11-07
CVE-2022-37866 Apache Ivy allows path traversal in the presence of a malicious repository — Apache Ivy CWE-22 7.5 - 2022-11-07
CVE-2022-42920 Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing — Apache Commons BCEL CWE-787 9.8 - 2022-11-07
CVE-2022-33684 Apache Pulsar C++/Python OAuth Clients prior to 3.0.0 were vulnerable to an MITM attack due to Disabled Certificate Validation — Apache Pulsar CWE-295 8.1 - 2022-11-04
CVE-2022-32287 Apache UIMA prior to 3.3.1 has a path traversal vulnerability when extracting (PEAR) archives — Apache UIMA CWE-22 9.1 - 2022-11-03
CVE-2022-43670 XSS in Sling CMS Reference App Taxonomy Path — Apache Sling App CMS CWE-79 5.4 - 2022-11-02
CVE-2022-43982 Apache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URL — Apache Airflow CWE-79 6.1 - 2022-11-02
CVE-2022-43985 Apache Airflow prior to 2.4.2 has an open redirect — Apache Airflow CWE-601 6.1 - 2022-11-02
CVE-2022-31777 Apache Spark XSS vulnerability in log viewer UI Javascript — Apache Spark CWE-74 5.4 - 2022-11-01
CVE-2022-34662 Apache DolphinScheduler prior to 3.0.0 allows path traversal — Apache DolphinScheduler CWE-22 6.5 - 2022-11-01
CVE-2022-42252 Apache Tomcat request smuggling via malformed content-length — Apache Tomcat CWE-444 8.2 - 2022-11-01

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.