Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,142 CVEs tagged to vendor apache566 Critical, 1,128 High, 1,349 Medium, 97 Low, 2 Unrated.

CVE-2025-24860

Published Feb 4, 2025

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-27137

Published Feb 4, 2025

In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23015

Published Feb 4, 2025

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cas…

CVSS 8.8 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2024-29869

Published Jan 28, 2025

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23953

Published Jan 28, 2025

Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacke…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24783

Published Jan 27, 2025

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-24814

Published Jan 27, 2025

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default i…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-52012

Published Jan 27, 2025

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53299

Published Jan 23, 2025

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23196

Published Jan 21, 2025

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability aris…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-23195

Published Jan 21, 2025

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure p…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-51941

Published Jan 21, 2025

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45479

Published Jan 21, 2025

SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45478

Published Jan 21, 2025

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23184

Published Jan 21, 2025

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be cl…

CVSS 5.9 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2024-45627

Published Jan 14, 2025

In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22828

Published Jan 13, 2025

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions fr…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-54676

Published Jan 8, 2025

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apach…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45033

Published Jan 8, 2025

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed w…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56512

Published Dec 28, 2024

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52046

Published Dec 25, 2024

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses.…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-43441

Published Dec 24, 2024

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommen…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45387

Published Dec 23, 2024

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "st…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-23945

Published Dec 23, 2024

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious act…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 651-675 of 3,142 CVEsPage 27 of 126