Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2021-44040 HTTP request line fuzzing attacks — Apache Traffic Server CWE-20 7.5 - 2022-03-23
CVE-2022-26779 Apache Cloudstack insecure random number generation affects project email invitation — Apache CloudStack 8.8 - 2022-03-15
CVE-2022-23943 mod_sed: Read/write beyond bounds — Apache HTTP Server CWE-787 9.1 - 2022-03-14
CVE-2022-22721 core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody — Apache HTTP Server CWE-190 9.1 - 2022-03-14
CVE-2022-22720 HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier — Apache HTTP Server CWE-444 9.8 - 2022-03-14
CVE-2022-22719 mod_lua Use of uninitialized value of in r:parsebody — Apache HTTP Server CWE-665 7.5 - 2022-03-14
CVE-2021-38296 Apache Spark Key Negotiation Vulnerability — Apache Spark CWE-294 7.5 - 2022-03-10
CVE-2022-25312 An XML external entity (XXE) injection vulnerability exists in the Apache Any23 RDFa XSLTStylesheet extractor — Apache Any23 9.1 - 2022-03-04
CVE-2022-26336 A carefully crafted TNEF file can cause an out of memory exception — poi-scratchpad CWE-770 5.5 - 2022-03-04
CVE-2022-24948 Apache JSPWiki Cross-site scripting vulnerability on User Preferences screen — Apache JSPWiki 6.1 - 2022-02-25
CVE-2022-24947 Apache JSPWiki CSRF Account Takeover — Apache JSPWiki 8.8 - 2022-02-25
CVE-2022-24288 Apache Airflow: RCE in example DAGs — Apache Airflow CWE-78 8.8 - 2022-02-25
CVE-2021-45229 Apache Airflow: Reflected XSS via Origin Query Argument in URL — Apache Airflow CWE-79 6.1 - 2022-02-25
CVE-2022-24289 Deserialization of untrusted data in the Hessian Component of Apache Cayenne 4.1 with older Java versions — Apache Cayenne CWE-502 8.8 - 2022-02-11
CVE-2022-24112 apisix/batch-requests plugin allows overwriting the X-REAL-IP header — Apache APISIX CWE-290 9.8 - 2022-02-11
CVE-2021-44521 Remote code execution for scripted UDFs — Apache Cassandra CWE-94 9.1 - 2022-02-11
CVE-2022-22931 Path traversal in Apache James 3.6.1 — Apache James CWE-22 4.3 - 2022-02-07
CVE-2022-23206 Server-Side Request Forgery in Traffic Ops endpoint POST /user/login/oauth — Apache Traffic Control CWE-918 7.5 - 2022-02-06
CVE-2022-23913 Apache ActiveMQ Artemis DoS — Apache ActiveMQ Artemis CWE-770 7.5 - 2022-02-04
CVE-2021-36152 Insecure TrustManager used in LDAP connections — Apache Gobblin 9.8 - 2022-02-04
CVE-2021-36151 Local Credentials Disclosure Vulnerability — Apache Gobblin 5.5 - 2022-02-04
CVE-2021-44451 API sensitive information leak — Apache Superset CWE-522 6.5 - 2022-02-01
CVE-2021-41571 Pulsar Admin API allows access to data from other tenants using getMessageById API — Apache Pulsar CWE-863 6.5 - 2022-02-01
CVE-2022-23181 Local privilege escalation with FileStore — Apache Tomcat CWE-367 7.0 - 2022-01-27
CVE-2022-22932 Path traversal flaws — Apache Karaf - - 2022-01-26
CVE-2021-41766 Insecure Java Deserialization in Apache Karaf — Apache Karaf 8.1 - 2022-01-26
CVE-2022-23945 Apache ShenYu missing authentication allows gateway registration — Apache ShenYu (incubating) CWE-862 9.1 - 2022-01-25
CVE-2022-23944 Apache ShenYu 2.4.1 Improper access control — Apache ShenYu (incubating) CWE-862 9.1 - 2022-01-25
CVE-2022-23223 Apache ShenYu Password leakage — Apache ShenYu (incubating) CWE-522 7.5 - 2022-01-25
CVE-2021-45029 Apache ShenYu 2.4.1 Groovy Code Injection & SpEL Injection — Apache ShenYu (incubating) CWE-94 9.8 - 2022-01-25

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.