Skip to main content

Vendor archive

apache CVEs

Beta · best-effort

3,154 CVEs tagged to vendor apache567 Critical, 1,138 High, 1,350 Medium, 97 Low, 2 Unrated.

CVE-2024-47250

Published Nov 26, 2024

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47249

Published Nov 26, 2024

Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and cras…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47248

Published Nov 26, 2024

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-d…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45719

Published Nov 22, 2024

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent no…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-52067

Published Nov 21, 2024

Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized a…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31141

Published Nov 19, 2024

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for custo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52318

Published Nov 18, 2024

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52317

Published Nov 18, 2024

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or respon…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52316

Published Nov 18, 2024

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may th…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2024-48962

Published Nov 18, 2024

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47208

Published Nov 18, 2024

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Us…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45791

Published Nov 18, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45505

Published Nov 18, 2024

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by au…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41151

Published Nov 18, 2024

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: befo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45784

Published Nov 15, 2024

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50306

Published Nov 14, 2024

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-50305

Published Nov 14, 2024

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users are recommended to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38479

Published Nov 14, 2024

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recomm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50386

Published Nov 12, 2024

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instances. Due to missing validation…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50378

Published Nov 8, 2024

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sen…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51504

Published Nov 7, 2024

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38286

Published Nov 7, 2024

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 1…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23590

Published Nov 4, 2024

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43383

Published Oct 31, 2024

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-bet…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 701-725 of 3,154 CVEsPage 29 of 127