Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-41313 Apache Doris: Timing Attack weakness — Apache DorisCWE-208 5.9AIMediumAI2024-03-12
CVE-2023-50740 Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged — Apache Linkis DataSourceCWE-532 7.5AIHighAI2024-03-06
CVE-2024-26580 Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability — Apache InLongCWE-502 9.1AICriticalAI2024-03-06
CVE-2024-27138 Apache Archiva: disabling user registration is not effective — Apache ArchivaCWE-863 7.5 -2024-03-01
CVE-2024-27139 Apache Archiva: incorrect authentication potentially leading to account takeover — Apache ArchivaCWE-863 9.1 -2024-03-01
CVE-2024-27140 Apache Archiva: reflected XSS — Apache ArchivaCWE-79 6.1 -2024-03-01
CVE-2023-50378 Apache Ambari: Various XSS problems — Apache AmbariCWE-79 6.1 -2024-03-01
CVE-2024-26280 Apache Airflow: Overly broad default permissions for Viewer/Ops (audit logs) — Apache AirflowCWE-276 2.7 -2024-03-01
CVE-2024-27906 Apache Airflow: Dag Code and Import Error Permissions Ignored — Apache AirflowCWE-862 4.3 -2024-02-29
CVE-2024-23946 Apache OFBiz: Path traversal or file inclusion — Apache OFBizCWE-22 9.1 -2024-02-28
CVE-2024-25065 Apache OFBiz: Path traversal allowing authentication bypass. — Apache OFBizCWE-22 9.1 -2024-02-28
CVE-2024-23807 Apache Xerces C++: Use-after-free on external DTD scan — Apache Xerces C++CWE-416 7.4 -2024-02-28
CVE-2024-26016 Apache Superset: Improper authorization validation on dashboards and charts import — Apache SupersetCWE-863 4.3 Medium2024-02-28
CVE-2024-24779 Apache Superset: Improper data authorization when creating a new dataset — Apache SupersetCWE-863 5.0 Medium2024-02-28
CVE-2024-24772 Apache Superset: Improper Neutralisation of custom SQL on embedded context — Apache SupersetCWE-89 4.3 Medium2024-02-28
CVE-2024-24773 Apache Superset: Improper validation of SQL statements allows for unauthorized access to data — Apache SupersetCWE-863 4.9 Medium2024-02-28
CVE-2024-27315 Apache Superset: Improper error handling on alerts — Apache SupersetCWE-209 4.3 Medium2024-02-28
CVE-2023-50380 Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server — Apache AmbariCWE-611 8.1 -2024-02-27
CVE-2024-21742 Apache James Mime4J: Mime4J DOM header injection — Apache James Mime4JCWE-74 5.3 -2024-02-27
CVE-2024-27905 Apache Aurora: padding oracle can allow construction an authentication cookie — Apache AuroraCWE-200 9.8 -2024-02-27
CVE-2023-51747 SMTP smuggling in Apache James — Apache James serverCWE-20 7.5 -2024-02-27
CVE-2023-51518 Apache James server: Privilege escalation via JMX pre-authentication deserialisation — Apache James serverCWE-502 7.8 -2024-02-27
CVE-2023-50379 Apache Ambari: authenticated users could perform command injection to perform RCE — Apache AmbariCWE-94 9.9 -2024-02-27
CVE-2024-22371 Apache Camel issue on ExchangeCreatedEvent — Apache Camel 2.9 Low2024-02-26
CVE-2024-23320 Apache DolphinScheduler: Arbitrary js execution as root for authenticated users — Apache DolphinSchedulerCWE-20 5.4 -2024-02-23
CVE-2024-22393 Apache Answer: Pixel Flood Attack by uploading the large pixel file — Apache AnswerCWE-434 6.5 -2024-02-22
CVE-2024-23349 Apache Answer: XSS vulnerability when submitting summary — Apache AnswerCWE-79 5.4 -2024-02-22
CVE-2024-26578 Apache Answer: Repeated submission at registration created duplicate users with the same name — Apache AnswerCWE-362 7.4 -2024-02-22
CVE-2024-25141 Apache Airflow Mongo Provider: Certificate validation isn't respected even if SSL is enabled for apache-airflow-providers-mongo — Apache Airflow Mongo ProviderCWE-295 7.5AIHighAI2024-02-20
CVE-2024-23114 Apache Camel: Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository — Apache CamelCWE-502 9.8 -2024-02-20

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.