Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,154 CVEs tagged to vendor apache567 Critical, 1,138 High, 1,350 Medium, 97 Low, 2 Unrated.

CVE-2024-45478

Published Jan 21, 2025

Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23184

Published Jan 21, 2025

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be cl…

CVSS 5.9 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2024-45627

Published Jan 14, 2025

In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22828

Published Jan 13, 2025

CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions fr…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-54676

Published Jan 8, 2025

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apach…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45033

Published Jan 8, 2025

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed w…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56512

Published Dec 28, 2024

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52046

Published Dec 25, 2024

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses.…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-43441

Published Dec 24, 2024

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommen…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45387

Published Dec 23, 2024

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "st…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-23945

Published Dec 23, 2024

Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious act…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56128

Published Dec 18, 2024

Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authent…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55633

Published Dec 12, 2024

Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Inc…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53677

Published Dec 11, 2024

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a mal…

CVSS 9.5 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2024-53949

Published Dec 9, 2024

Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affec…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53948

Published Dec 9, 2024

Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53947

Published Dec 9, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not chec…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-41137

Published Dec 5, 2024

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Co…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45106

Published Dec 3, 2024

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other use…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52338

Published Nov 28, 2024

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-51569

Published Nov 26, 2024

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and inval…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 676-700 of 3,154 CVEsPage 28 of 127