Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2024-22369 Apache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepository — Apache CamelCWE-502 9.8 -2024-02-20
CVE-2023-51770 Apache DolphinScheduler: Arbitrary File Read Vulnerability — Apache DolphinSchedulerCWE-94 7.5AIHighAI2024-02-20
CVE-2023-50270 Apache DolphinScheduler: Session do not expire after password change — Apache DolphinSchedulerCWE-613 9.1AICriticalAI2024-02-20
CVE-2023-49250 Apache DolphinScheduler: Insecure TLS TrustManager used in HttpUtil — Apache DolphinSchedulerCWE-295 7.4AIHighAI2024-02-20
CVE-2023-49109 Remote Code Execution in Apache Dolphinscheduler — Apache DolphinSchedulerCWE-94 9.8AICriticalAI2024-02-20
CVE-2024-25710 Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file — Apache Commons CompressCWE-835 8.1 High2024-02-19
CVE-2024-26308 Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file — Apache Commons CompressCWE-770 7.5 -2024-02-19
CVE-2024-23952 Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104) — Apache SupersetCWE-400 6.5 Medium2024-02-14
CVE-2023-50291 Apache Solr: System Property redaction logic inconsistency can lead to leaked passwords — Apache SolrCWE-522 7.5 -2024-02-09
CVE-2023-50292 Apache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated users — Apache SolrCWE-732 9.8 -2024-02-09
CVE-2023-50298 Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions — Apache SolrCWE-200 7.5 -2024-02-09
CVE-2023-50386 Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets — Apache SolrCWE-434 9.8 -2024-02-09
CVE-2024-23452 Apache bRPC: HTTP request smuggling vulnerability — Apache bRPCCWE-444 8.2 -2024-02-08
CVE-2023-39196 Apache Ozone: Missing mutual TLS authentication in one of the service internal Ozone Storage Container Manager endpoints — Apache OzoneCWE-287 5.3 Medium2024-02-07
CVE-2023-51437 Apache Pulsar: Timing attack in SASL token signature verification — Apache PulsarCWE-203 7.4 High2024-02-07
CVE-2024-23673 Apache Sling Servlets Resolver: Malicious code execution via path traversal — Apache Sling Servlets ResolverCWE-22 8.5 High2024-02-06
CVE-2023-44313 Apache ServiceComb Service-Center: attacker can perform SSRF through the frontend API — Apache ServiceComb Service-CenterCWE-918 7.6 High2024-01-31
CVE-2023-44312 Apache ServiceComb Service-Center: attacker can query all environment variables of the service-center server — Apache ServiceComb Service-CenterCWE-200 5.8 Medium2024-01-31
CVE-2023-29055 Apache Kylin: Insufficiently protected credentials in config file — Apache KylinCWE-522 9.8 -2024-01-29
CVE-2023-50944 Apache Airflow: Bypass permission verification to read code of other dags — Apache AirflowCWE-862 6.5 -2024-01-24
CVE-2023-50943 Apache Airflow: Potential pickle deserialization vulnerability in XComs — Apache AirflowCWE-502 8.2 -2024-01-24
CVE-2023-51702 Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service — Apache Airflow CNCF Kubernetes providerCWE-532 6.5 -2024-01-24
CVE-2023-49657 Apache Superset: Stored XSS in Dashboard Title and Chart Title — Apache SupersetCWE-79 9.6 Critical2024-01-23
CVE-2024-21733 Apache Tomcat: Leaking of unrelated request bodies in default error page — Apache TomcatCWE-209 7.5 -2024-01-19
CVE-2023-46226 Apache IoTDB: Remote Code Execution (RCE) risk via the UDF — Apache IoTDB 9.8 -2024-01-15
CVE-2023-46749 Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting — Apache ShiroCWE-22 9.8 -2024-01-15
CVE-2023-50290 Apache Solr: Host environment variables are published via the Metrics API — Apache SolrCWE-200 7.5 -2024-01-15
CVE-2023-49619 Apache Answer: Repeated submissions using scripts resulted in an abnormal number of collections for questions. — Apache AnswerCWE-362--AI2024-01-10
CVE-2023-51441 Apache Axis 1.x (EOL) may allow SSRF when untrusted input is passed to the service admin HTTP API — Apache AxisCWE-918 8.7 -2024-01-06
CVE-2023-51784 Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager — Apache InLongCWE-94 9.8AICriticalAI2024-01-03

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.