Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2021-28656 Apache Zeppelin: CSRF vulnerability in the Credentials page — Apache ZeppelinCWE-352 8.8AIHighAI2024-04-09
CVE-2024-31860 Apache Zeppelin: Path traversal vulnerability — Apache ZeppelinCWE-22 6.5AIMediumAI2024-04-09
CVE-2024-24746 Apache NimBLE: Denial of service in NimBLE Bluetooth stack — Apache NimBLECWE-835 6.5 -2024-04-06
CVE-2024-27316 Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames — Apache HTTP ServerCWE-770 7.5 -2024-04-04
CVE-2024-24795 Apache HTTP Server: HTTP Response Splitting in multiple modules — Apache HTTP ServerCWE-113 9.1 -2024-04-04
CVE-2023-38709 Apache HTTP Server: HTTP response splitting — Apache HTTP Server 7.5 -2024-04-04
CVE-2024-29008 Apache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instance — Apache CloudStackCWE-20 9.6 -2024-04-04
CVE-2024-29007 Apache CloudStack: When downloading templates or ISOs, the management server and SSVM follow HTTP redirects with potentially dangerous consequences — Apache CloudStackCWE-918 8.1 -2024-04-04
CVE-2024-29006 Apache CloudStack: x-forwarded-for HTTP header parsed by default — Apache CloudStackCWE-290 8.1 -2024-04-04
CVE-2024-29834 Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints — Apache PulsarCWE-863 6.4 Medium2024-04-02
CVE-2024-23537 Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. — Apache FineractCWE-269 8.4 High2024-03-29
CVE-2024-23538 Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. — Apache FineractCWE-89 9.9 Critical2024-03-29
CVE-2024-23539 Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. — Apache FineractCWE-89 8.3 High2024-03-29
CVE-2024-29735 Apache Airflow: Potentially harmful permission changing by log task handler — Apache AirflowCWE-281 8.1AIHighAI2024-03-26
CVE-2024-27438 Apache Doris: Downloading arbitrary remote jar files resulting in remote command execution — Apache DorisCWE-494 8.8AIHighAI2024-03-21
CVE-2024-26307 Apache Doris: Possible race condition — Apache DorisCWE-362 6.5AIMediumAI2024-03-21
CVE-2024-29131 Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() — Apache Commons ConfigurationCWE-787 9.8AICriticalAI2024-03-21
CVE-2024-29133 Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree — Apache Commons ConfigurationCWE-787 9.8AICriticalAI2024-03-21
CVE-2024-27439 Apache Wicket: Possible bypass of CSRF protection — Apache WicketCWE-352 8.8 -2024-03-19
CVE-2024-24683 Apache Hop Engine: ID isn't escaped when generating HTML — Apache Hop EngineCWE-20 8.2AIHighAI2024-03-19
CVE-2024-28752 Apache CXF SSRF Vulnerability using the Aegis databinding — Apache CXFCWE-918 9.1 -2024-03-15
CVE-2024-23944 Apache ZooKeeper: Information disclosure in persistent watcher handling — Apache ZooKeeperCWE-862 5.3 -2024-03-15
CVE-2024-28746 Apache Airflow: Ignored Airflow Permissions — Apache AirflowCWE-281 4.3AIMediumAI2024-03-14
CVE-2024-23672 Apache Tomcat: WebSocket DoS with incomplete closing handshake — Apache TomcatCWE-459 7.5AIHighAI2024-03-13
CVE-2024-24549 Apache Tomcat: HTTP/2 header handling DoS — Apache TomcatCWE-20 7.5AIHighAI2024-03-13
CVE-2024-27894 Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying — Apache PulsarCWE-20 8.5 High2024-03-12
CVE-2024-27317 Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification — Apache PulsarCWE-22 8.4 High2024-03-12
CVE-2024-27135 Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution — Apache PulsarCWE-913 8.5 High2024-03-12
CVE-2022-34321 Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint — Apache PulsarCWE-306 8.2 High2024-03-12
CVE-2024-28098 Apache Pulsar: Improper Authorization For Topic-Level Policy Management — Apache PulsarCWE-863 6.4 Medium2024-03-12

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.