Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2021-44790 Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier — Apache HTTP Server CWE-787 9.8 - 2021-12-20
CVE-2021-43083 Apache PLC4X 0.9.0 Buffer overflow in PLC4C via crafted server response — Apache PLC4X CWE-119 8.1 - 2021-12-19
CVE-2021-45105 Apache Log4j2 does not always protect from infinite recursion in lookup evaluation — Apache Log4j2 CWE-20 5.9 - 2021-12-18
CVE-2021-44145 Apache NiFi information disclosure by XXE — Apache NiFi 6.5 - 2021-12-17
CVE-2021-45046 Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack — Apache Log4j CWE-917 9.0 - 2021-12-14
CVE-2021-44549 SMTPS server hostname not checked when making TLS connection to SMTPS server — Apache Sling Commons Messaging Mail CWE-295 7.4 - 2021-12-14
CVE-2021-4104 Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2 — Apache Log4j 1.x CWE-502 7.5 - 2021-12-14
CVE-2021-44228 Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints — Apache Log4j2 CWE-502 9.9 - 2021-12-10
CVE-2021-43410 airavata-django-portal allows CRLF log injection because of the lack of escaping in the log statements — Apache Airavata Django Portal CWE-117 5.3 - 2021-12-09
CVE-2021-44140 Arbitrary file deletion on logout — Apache JSPWiki 9.1 - 2021-11-24
CVE-2021-40369 XSS vulnerability on Denounce plugin — Apache JSPWiki 6.1 - 2021-11-24
CVE-2021-43557 Path traversal in request_uri variable — Apache APISIX 9.1 - 2021-11-22
CVE-2021-41532 Unauthenticated access to Ozone Recon HTTP endpoints — Apache Ozone CWE-200 5.3 - 2021-11-19
CVE-2021-39236 Owners of the S3 tokens are not validated — Apache Ozone CWE-862 8.1 - 2021-11-19
CVE-2021-39235 Access mode of block tokens are not enforced — Apache Ozone CWE-732 8.1 - 2021-11-19
CVE-2021-39234 Raw block data can be read bypassing ACL/authorization — Apache Ozone CWE-20 6.8 - 2021-11-19
CVE-2021-39233 Container-related datanode operations can be called without authorization — Apache Ozone CWE-306 7.5 - 2021-11-19
CVE-2021-39232 Missing admin check for SCM related admin commands — Apache Ozone CWE-862 8.8 - 2021-11-19
CVE-2021-39231 Missing authentication/authorization on internal RPC endpoints — Apache Ozone CWE-862 9.1 - 2021-11-19
CVE-2021-36372 Original block tokens are persisted and can be retrieved — Apache Ozone CWE-273 9.8 - 2021-11-19
CVE-2021-42250 Possible log injection — Apache Superset CWE-117 6.5 - 2021-11-17
CVE-2021-37580 Apache ShenYu Admin bypass JWT authentication — Apache ShenYu Admin CWE-287 9.8 - 2021-11-16
CVE-2021-41972 Credentials leak — Apache Superset CWE-522 6.5 - 2021-11-12
CVE-2021-43350 LDAP filter injection vulnerability in Traffic Ops — Apache Traffic Control CWE-90 9.8 - 2021-11-11
CVE-2021-26558 Deserialization of Untrusted Data — Apache ShardingSphere-UI CWE-502 7.5 - 2021-11-11
CVE-2021-43082 heap-buffer-overflow with stats-over-http plugin — Apache Traffic Server CWE-120 9.8 - 2021-11-03
CVE-2021-41585 ATS stops accepting connections on FreeBSD — Apache Traffic Server 7.5 - 2021-11-03
CVE-2021-38161 Not validating origin TLS certificate — Apache Traffic Server CWE-287 7.7 - 2021-11-03
CVE-2021-37149 Request Smuggling - multiple attacks — Apache Traffic Server CWE-20 7.5 - 2021-11-03
CVE-2021-37148 Request Smuggling - transfer encoding validation — Apache Traffic Server CWE-20 7.5 - 2021-11-03

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.