Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1685

Browse all 1685 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-37582 Apache RocketMQ: Possible remote code execution when using the update configuration function — Apache RocketMQCWE-94 9.8 -2023-07-12
CVE-2023-22888 Apache Airflow: Scheduler remote DoS — Apache AirflowCWE-20 6.5 -2023-07-12
CVE-2023-36543 Apache Airflow: ReDoS via dags function — Apache AirflowCWE-1333 6.5 -2023-07-12
CVE-2022-46651 Apache Airflow: Security vulnerability on AirFlow Connections — Apache AirflowCWE-200 6.5 -2023-07-12
CVE-2023-22887 Apache Airflow path traversal by authenticated user — Apache AirflowCWE-22 6.5 -2023-07-12
CVE-2023-35908 Apache Airflow: Access to DAGs without relevant permission — Apache AirflowCWE-863 5.3 -2023-07-12
CVE-2023-30428 Apache Pulsar Broker: Incorrect Authorization Validation for Rest Producer — Apache Pulsar BrokerCWE-863 8.2 High2023-07-12
CVE-2023-30429 Apache Pulsar: Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy — Apache PulsarCWE-863 9.6 Critical2023-07-12
CVE-2023-31007 Apache Pulsar: Broker does not always disconnect client when authentication data expires — Apache PulsarCWE-287--2023-07-12
CVE-2023-37579 Apache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials — Apache Pulsar Function WorkerCWE-863 8.2 High2023-07-12
CVE-2023-32200 Apache Jena: Exposure of execution in script engine expressions. — Apache JenaCWE-917 4.6 -2023-07-12
CVE-2023-34442 Apache Camel JIRA: Temporary file information disclosure in Camel-Jira — Apache Camel JIRACWE-200 7.5 -2023-07-10
CVE-2023-35887 Apache MINA SSHD: Information disclosure bugs with RootedFilesystem — Apache MINA SSHDCWE-22 5.0 Medium2023-07-10
CVE-2023-33008 Apache Johnzon: Prevent inefficient internal conversion from BigDecimal at large scale — Apache JohnzonCWE-502 7.5 -2023-07-07
CVE-2023-34150 Apache Any23: Possible excessive allocation of resources reading input. — Apache Any23CWE-20 6.5 Medium2023-07-05
CVE-2023-35797 Apache Airflow Hive Provider Beeline RCE with Principal — Apache Airflow Apache Hive ProviderCWE-20 9.8 -2023-07-03
CVE-2023-22886 Apache Airflow JDBC Provider: RCE Vulnerability — Apache Airflow JDBC ProviderCWE-20 9.8 -2023-06-29
CVE-2023-35798 Airflow Apache ODBC and MSSQL Providers Arbitrary File Read Vulnerability — Apache Airflow ODBC ProviderCWE-20 8.8 -2023-06-27
CVE-2023-34395 Apache Airflow ODBC Provider: Remote code execution vulnerability — Apache Airflow ODBC ProviderCWE-88 9.8 -2023-06-27
CVE-2023-31469 Apache StreamPipes: Privilege escalation through non-admin user — Apache StreamPipesCWE-269 8.8 -2023-06-23
CVE-2023-34981 Apache Tomcat: AJP response header mix-up — Apache Tomcat 7.5 -2023-06-21
CVE-2023-34340 Apache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentials — Apache AccumuloCWE-287 9.1 -2023-06-21
CVE-2023-35005 Apache Airflow: Information disclosure on configuration view — Apache AirflowCWE-200 7.5 -2023-06-19
CVE-2023-34396 Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms — Apache StrutsCWE-770 4.3 Medium2023-06-14
CVE-2023-34149 Apache Struts: DoS via OOM owing to not properly checking of list bounds — Apache StrutsCWE-770 4.3 Medium2023-06-14
CVE-2023-30631 Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work — Apache Traffic ServerCWE-20 7.5 -2023-06-14
CVE-2023-33933 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic ServerCWE-200 7.5 -2023-06-14
CVE-2022-47184 Apache Traffic Server: The TRACE method can be use to disclose network information — Apache Traffic ServerCWE-200 7.5 -2023-06-14
CVE-2023-34212 Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components — Apache NiFiCWE-502 8.8 -2023-06-12
CVE-2023-34468 Apache NiFi: Potential Code Injection with Database Services using H2 — Apache NiFiCWE-94 8.8 -2023-06-12

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.