Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2021-37147 Request Smuggling - LF line ending — Apache Traffic Server CWE-20 7.5 - 2021-11-03
CVE-2021-27644 DolphinScheduler mysql jdbc connector parameters deserialize remote code execution — Apache DolphinScheduler CWE-264 8.8 - 2021-11-01
CVE-2021-41973 Apache MINA HTTP listener DOS — Apache MINA CWE-835 6.5 - 2021-11-01
CVE-2021-40865 Unsafe Pre-Authentication Deserialization In Workers — Apache Storm CWE-502 9.8 - 2021-10-25
CVE-2021-38294 Shell Command Injection Vulnerability in Nimbus Thrift Server — Apache Storm CWE-74 9.8 - 2021-10-25
CVE-2021-41971 Possible SQL Injection when template processing is enabled — Apache Superset CWE-89 8.8 - 2021-10-18
CVE-2021-32609 XSS vulnerability on Explore page — Apache Superset CWE-79 6.4 - 2021-10-18
CVE-2021-42340 DoS via memory leak with WebSocket connections — Apache Tomcat CWE-772 7.5 - 2021-10-14
CVE-2021-38295 Privilege escalation vulnerability when using HTML attachments — Apache CouchDB 7.3 - 2021-10-14
CVE-2021-42009 Apache Traffic Control Traffic Ops Email Injection Vulnerability — Apache Traffic Control CWE-20 4.3 - 2021-10-12
CVE-2021-41832 Content Manipulation with Certificate Validation Attack — Apache OpenOffice CWE-347 7.5 - 2021-10-11
CVE-2021-41831 Timestamp Manipulation with Signature Wrapping — Apache OpenOffice CWE-347 4.0 - 2021-10-11
CVE-2021-41830 Double Certificate Attack — Apache OpenOffice CWE-347 7.5 - 2021-10-11
CVE-2021-42013 Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) — Apache HTTP Server CWE-22 9.8 - 2021-10-07
CVE-2021-40439 Billion Laughs — Apache OpenOffice CWE-611 8.1 - 2021-10-07
CVE-2021-28129 DEB packaging for Apache OpenOffice 4.1.8 installed with a non-root userid and groupid — Apache OpenOffice CWE-284 7.1 - 2021-10-07
CVE-2021-41773 Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 — Apache HTTP Server CWE-22 9.1 - 2021-10-05
CVE-2021-41524 null pointer dereference in h2 fuzzing — Apache HTTP Server CWE-476 7.5 - 2021-10-05
CVE-2021-41616 Apache ddlutils 1.0 readobject vulnerability — Apache DB ddlutils CWE-502 9.8 - 2021-09-30
CVE-2021-36749 Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920) — Apache Druid 6.5 - 2021-09-24
CVE-2021-33035 Buffer overflow from a crafted DBF file — Apache OpenOffice CWE-120 7.8 - 2021-09-23
CVE-2021-38153 Timing Attack Vulnerability for Apache Kafka Connect and Clients — Apache Kafka CWE-203 5.9 - 2021-09-22
CVE-2021-40690 Bypass of the secureValidation property — Apache Santuario CWE-200 7.5 - 2021-09-19
CVE-2021-41303 Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass — Apache Shiro CWE-287 9.8 - 2021-09-17
CVE-2021-41079 Apache Tomcat DoS with unexpected TLS packet — Apache Tomcat CWE-20 7.5 - 2021-09-16
CVE-2021-40438 mod_proxy SSRF — Apache HTTP Server CWE-918 8.1 - 2021-09-16
CVE-2021-39275 ap_escape_quotes buffer overflow — Apache HTTP Server 9.8 - 2021-09-16
CVE-2021-39239 XML External Entity (XXE) vulnerability — Apache Jena 7.5 - 2021-09-16
CVE-2021-36160 mod_proxy_uwsgi out of bound read — Apache HTTP Server CWE-125 7.5 - 2021-09-16
CVE-2021-34798 NULL pointer dereference in httpd core — Apache HTTP Server CWE-476 7.5 - 2021-09-16

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.