Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2022-28220 STARTTLS command injection in Apache JAMES — Apache James CWE-77 7.5 - 2022-09-08
CVE-2022-38370 No authorization of DatabaseConnectController in grafana-connector. — Apache IoTDB 5.3 - 2022-09-05
CVE-2022-38369 Login check vulnerability by session Id — Apache IoTDB 8.1 - 2022-09-05
CVE-2022-38054 Session Fixation — Apache Airflow CWE-384 9.8 - 2022-09-02
CVE-2022-38170 Overly permissive umask for daemons — Apache Airflow 4.7 - 2022-09-02
CVE-2022-29158 Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz — Apache OFBiz CWE-1333 7.5 - 2022-09-02
CVE-2022-29063 Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz — Apache OFBiz CWE-502 9.8 - 2022-09-02
CVE-2022-25813 Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz — Apache OFBiz CWE-1336 7.5 - 2022-09-02
CVE-2022-25371 Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz — Apache OFBiz CWE-22 9.8 - 2022-09-02
CVE-2022-25370 Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz — Apache OFBiz CWE-79 5.4 - 2022-09-02
CVE-2022-37435 Apache ShenYu Admin Improper Privilege Management — Apache ShenYu CWE-732 8.8 - 2022-09-01
CVE-2022-37023 Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11 — Apache Geode CWE-502 8.8 - 2022-08-31
CVE-2022-37022 Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11 — Apache Geode CWE-502 9.8 - 2022-08-31
CVE-2022-37021 Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8. — Apache Geode CWE-502 9.8 - 2022-08-31
CVE-2021-25642 Apache Hadoop YARN remote code execution in ZKConfigurationStore of capacity scheduler — Apache Hadoop CWE-502 8.8 - 2022-08-25
CVE-2022-22728 libapreq2 multipart form parse memory corruption — libapreq2 CWE-120 7.5 - 2022-08-25
CVE-2022-35278 HTML Injection in ActiveMQ Artemis Web Console — Apache ActiveMQ Artemis CWE-80 6.1 - 2022-08-23
CVE-2022-34916 Improper Input Validation (JNDI Injection) in JMSMessageConsumer — Apache Flume CWE-20 9.8 - 2022-08-21
CVE-2022-38362 Docker Provider <3.0 RCE vulnerability in example dag — Apache Airflow 8.8 - 2022-08-16
CVE-2022-37401 Apache OpenOffice Weak Master Keys — Apache OpenOffice CWE-331 8.8 - 2022-08-13
CVE-2022-37400 Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password — Apache OpenOffice CWE-330 6.5 - 2022-08-13
CVE-2022-31779 Improper HTTP/2 scheme and method validation — Apache Traffic Server CWE-20 7.5 - 2022-08-10
CVE-2022-25763 Improper input validation on HTTP/2 headers — Apache Traffic Server CWE-444 7.5 - 2022-08-10
CVE-2021-37150 Protocol vs scheme mismatch — Apache Traffic Server CWE-20 7.5 - 2022-08-10
CVE-2022-28129 Insufficient Validation of HTTP/1.x Headers — Apache Traffic Server CWE-20 7.5 - 2022-08-10
CVE-2022-31778 Transfer-Encoding not treated as hop-by-hop — Apache Traffic Server CWE-20 7.5 - 2022-08-10
CVE-2022-31780 HTTP/2 framing vulnerabilities — Apache Traffic Server CWE-20 7.5 - 2022-08-10
CVE-2022-36125 Integer overflow when reading corrupted .avro file in Avro Rust SDK — Apache Avro CWE-20 7.5 - 2022-08-09
CVE-2022-36124 Memory overconsumption in Avro Rust SDK — Apache Avro CWE-770 7.5 - 2022-08-09
CVE-2022-35724 Denial of service while reading data in Avro Rust SDK — Apache Avro CWE-20 7.5 - 2022-08-09

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.