Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2022-26884 Apache DolphinScheduler exposes files without authentication — Apache DolphinScheduler CWE-22 6.5 - 2022-10-28
CVE-2022-39944 The Apache Linkis JDBC EngineConn module has a RCE Vulnerability — Apache Linkis 8.8 - 2022-10-26
CVE-2022-42468 Apache Flume prior to 1.11.0 has an Improper Input Validation (JNDI Injection) in JMSSource — Apache Flume CWE-20 9.8 - 2022-10-26
CVE-2022-43766 Apache IoTDB prior to 0.13.3 allows DoS — Apache IoTDB 7.5 - 2022-10-26
CVE-2022-34870 Apache Geode stored Cross-Site Scripting (XSS) via data injection vulnerability in Pulse web application — Apache Geode 5.4 - 2022-10-25
CVE-2022-41704 Apache Batik prior to 1.16 allows RCE when loading untrusted SVG input — Apache XML Graphics 7.5 - 2022-10-25
CVE-2022-42890 Apache Batik prior to 1.16 allows RCE via scripting — Apache XML Graphics 7.5 - 2022-10-25
CVE-2021-42010 CRLF log injection — Apache Heron (Incubating) 9.8 - 2022-10-24
CVE-2022-42466 XSS vulnerability, eg for String properties. — Apache Isis CWE-79 6.1 - 2022-10-19
CVE-2022-42467 h2 webconsole (available only in prototype mode) should nevertheless be disabled by default. — Apache Isis CWE-1188 7.5 - 2022-10-19
CVE-2022-39198 Apache Dubbo Hession Deserialization Vulnerability Gadgets Bypass — Apache Dubbo CWE-502 9.8 - 2022-10-18
CVE-2022-24697 Apache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parameters — Apache Kylin 9.8 - 2022-10-13
CVE-2022-42889 Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults — Apache Commons Text 9.8 - 2022-10-13
CVE-2022-40664 Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher — Apache Shiro CWE-287 9.8 - 2022-10-12
CVE-2022-41672 Session still functional after user is deactivated — Apache Airflow CWE-613 8.1 - 2022-10-07
CVE-2021-43980 Apache Tomcat: Information disclosure — Apache Tomcat CWE-362 3.7 - 2022-09-28
CVE-2022-33683 Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack — Apache Pulsar CWE-295 5.9 - 2022-09-23
CVE-2022-33682 Disabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack — Apache Pulsar CWE-295 5.9 - 2022-09-23
CVE-2022-33681 Improper Hostname Verification in Java Client and Proxy can expose authentication data via MITM — Apache Pulsar CWE-295 5.9 - 2022-09-23
CVE-2022-24280 Apache Pulsar Proxy target broker address isn't validated — Apache Pulsar CWE-20 7.5 - 2022-09-23
CVE-2022-26112 Pinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support — Apache Pinot 9.8 - 2022-09-23
CVE-2022-40705 Apache SOAP: XML External Entity Injection (XXE) allows unauthenticated users to read arbitrary files via HTTP — Apache SOAP CWE-611 7.5 - 2022-09-22
CVE-2022-38398 Server-Side Request Forgery Information Disclosure Vulnerability — Apache XML Graphics CWE-918 7.5 - 2022-09-22
CVE-2022-38648 PDFTranscoder does not block external resources — Apache XML Graphics CWE-918 5.3 - 2022-09-22
CVE-2022-40146 Jar url should be blocked by DefaultScriptSecurity — Apache XML Graphics CWE-918 7.5 - 2022-09-22
CVE-2022-40754 Open Redirect — Apache Airflow CWE-601 6.1 - 2022-09-21
CVE-2022-40604 Format String Vulnerability — Apache Airflow CWE-134 7.5 - 2022-09-21
CVE-2022-40955 Deserialization attack in Apache InLong prior to version 1.3.0 allows RCE via JDBC — Apache InLong CWE-502 8.8 - 2022-09-20
CVE-2022-34917 Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers — Apache Kafka CWE-789 7.5 - 2022-09-20
CVE-2022-39135 Apache Calcite: potential XEE attacks — Apache Calcite CWE-611 9.8 - 2022-09-11

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.