Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-41180 Apache NiFi MiNiFi C++: Incorrect Certificate Validation in InvokeHTTP for MiNiFi C++ — Apache NiFi MiNiFi C++CWE-295 5.9 -2023-09-03
CVE-2023-40195 Apache Airflow Spark Provider Deserialization Vulnerability RCE — Apache Airflow Spark ProviderCWE-502 8.0 -2023-08-28
CVE-2023-27604 Apache Airflow Sqoop Provider: Airflow Sqoop Provider RCE Vulnerability — Apache Airflow Sqoop ProviderCWE-20 8.8 -2023-08-28
CVE-2023-41080 Apache Tomcat: Open redirect with FORM authentication — Apache TomcatCWE-601 6.1 -2023-08-25
CVE-2023-39441 Apache Airflow SMTP Provider, Apache Airflow IMAP Provider, Apache Airflow: SMTP/IMAP client components allowed MITM due to missing Certificate Validation — Apache Airflow SMTP ProviderCWE-295 6.8 -2023-08-23
CVE-2023-37379 Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" feature — Apache AirflowCWE-400 8.1 -2023-08-23
CVE-2023-40273 Session fixation in Apache Airflow web interface — Apache AirflowCWE-384 8.8 -2023-08-23
CVE-2022-44729 Apache XML Graphics Batik: Information disclosure vulnerability — Apache XML Graphics BatikCWE-918 8.2 -2023-08-22
CVE-2022-44730 Apache XML Graphics Batik: Information disclosure vulnerability — Apache XML Graphics BatikCWE-918 6.5 -2023-08-22
CVE-2022-46751 Apache Ivy: XML External Entity vulnerability in Apache Ivy — Apache IvyCWE-611 8.6 -2023-08-21
CVE-2023-40037 Apache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs — Apache NiFiCWE-184 8.1 -2023-08-18
CVE-2023-40272 Apache Airflow Spark Provider Arbitrary File Read via JDBC — Apache Airflow Spark ProviderCWE-20 7.5 -2023-08-17
CVE-2023-39553 Apache Airflow Drill Provider Arbitrary File Read Vulnerability — Apache Airflow Drill ProviderCWE-20 7.5 -2023-08-11
CVE-2023-33934 Apache Traffic Server: Differential fuzzing for HTTP request parsing discrepancies — Apache Traffic ServerCWE-444 8.2 -2023-08-09
CVE-2022-47185 Apache Traffic Server: Invalid Range header causes a crash — Apache Traffic ServerCWE-20 8.2 -2023-08-09
CVE-2023-37581 Apache Roller: Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross Site Scripting (XSS) even on a Roller site configured for untrusted users. — Apache RollerCWE-79 5.4 -2023-08-06
CVE-2023-39508 Apache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledges — Apache AirflowCWE-250 8.8 -2023-08-05
CVE-2023-36542 Apache NiFi: Potential Code Injection with Properties Referencing Remote Resources — Apache NiFiCWE-94 8.8 -2023-07-29
CVE-2023-38647 Apache Helix: Deserialization vulnerability in Helix workflow and REST — Apache HelixCWE-502 9.8 -2023-07-26
CVE-2023-38435 Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole plugin — Apache Felix Healthcheck Webconsole PluginCWE-79 6.1 -2023-07-25
CVE-2023-37895 Apache Jackrabbit RMI access can lead to RCE — Apache Jackrabbit Webapp (jackrabbit-webapp)CWE-502 9.8 -2023-07-25
CVE-2023-35088 Apache InLong: SQL injection in audit endpoint — Apache InLongCWE-89 9.8 -2023-07-25
CVE-2023-34434 Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param — Apache InLongCWE-502 7.5 -2023-07-25
CVE-2023-34189 Apache InLong: General user can delete and update process — Apache InLongCWE-668 9.1 -2023-07-25
CVE-2023-34478 Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests. — Apache ShiroCWE-22 9.8 -2023-07-24
CVE-2023-28754 ShardingSphere-Agent: Deserialization vulnerability in ShardingSphere Agent — ShardingSphere-AgentCWE-502 7.8 -2023-07-19
CVE-2023-26512 Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data — Apache EventMesh (incubating) RabbitMQ connectorCWE-502 9.8 -2023-07-17
CVE-2023-37415 Apache Airflow Apache Hive Provider: Improper Input Validation in Hive Provider with proxy_user — Apache Airflow Apache Hive ProviderCWE-20 7.1 -2023-07-13
CVE-2022-45855 Apache Ambari: Allows authenticated metrics consumers to perform RCE — Apache AmbariCWE-917 8.0 High2023-07-12
CVE-2022-42009 Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application. — Apache AmbariCWE-917 8.0 High2023-07-12

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.