Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Pinot HIGH 7.5
CVE-2024-39676

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. U…

Fix: 1.0.0+
Fix from $1,950 2024-07-24
Rocketmq HIGH 8.8
CVE-2024-23321

For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i…

Fix: 5.3.0+
Fix from $1,950 2024-07-22
Allura HIGH 7.5
CVE-2024-36471

Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imp…

Fix: 1.17.0+
Fix from $1,950 2024-06-10
Aurora CRITICAL 9.1
CVE-2024-27905

** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing inte…

Mitigation only
Fix from $2,300 2024-02-27
Solr HIGH 7.5
CVE-2023-50298

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, fr…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Servicecomb HIGH 7.5
CVE-2023-44312

Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Cente…

Fix: 2.2.0+
Fix from $1,950 2024-01-31
Solr MEDIUM 6.5
CVE-2023-50290EPSS 68%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment v…

Fix: 9.3.0+
Fix from $1,600 2024-01-15
Ofbiz HIGH 7.5
CVE-2023-50968EPSS 63%

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. Th…

Fix: 18.12.11+
Fix from $1,950 2023-12-26
Couchdb MEDIUM 5.7
CVE-2023-45725

Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the do…

Fix: after 3.3.2
Fix from $1,600 2023-12-13
Dolphinscheduler HIGH 7.5
CVE-2023-49068

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects Apache DolphinScheduler: befor…

Fix: 3.2.1+
Fix from $1,950 2023-11-27
Dolphinscheduler HIGH 7.5
CVE-2023-48796

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information exposed to unauthorized actors …

Fix: 3.0.2+
Fix from $1,950 2023-11-24
Storm MEDIUM 5.5
CVE-2023-43123

On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set th…

Fix: 2.6.0+
Fix from $1,600 2023-11-23
Airflow MEDIUM 6.5
CVE-2023-42781

Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…

Fix: 2.7.3+
Fix from $1,600 2023-11-12
Traffic Server HIGH 7.5
CVE-2023-41752

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.…

Fix: 8.1.9 / 9.2.3+
Fix from $1,950 2023-10-17
Airflow MEDIUM 6.5
CVE-2023-42780

Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, …

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Airflow MEDIUM 6.5
CVE-2023-42663

Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read informat…

Fix: 2.7.2+
Fix from $1,600 2023-10-14
Airflow MEDIUM 6.5
CVE-2023-40712

Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, …

Fix: 2.7.1+
Fix from $1,600 2023-09-12
Airflow HIGH 8.1
CVE-2023-37379

Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection ed…

Fix: 2.7.0+
Fix from $1,950 2023-08-23
Airflow HIGH 8.8
CVE-2023-39508

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apach…

Fix: 2.6.0+
Fix from $1,950 2023-08-05
Airflow MEDIUM 6.5
CVE-2022-46651

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Co…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-35005

In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact…

Fix: 2.6.2+
Fix from $1,600 2023-06-19
Traffic Server HIGH 7.5
CVE-2023-33933

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Traffic Server HIGH 7.5
CVE-2022-47184

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apach…

Fix: 8.1.7 / 9.2.1+
Fix from $1,950 2023-06-14
Couchdb MEDIUM 5.3
CVE-2023-26268

Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design d…

Fix: 3.2.3 / 3.3.2+
Fix from $1,600 2023-05-02
Dolphinscheduler HIGH 7.5
CVE-2022-26885

When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.

Fix: 2.0.6+
Fix from $1,950 2022-11-24
Airflow HIGH 7.5
CVE-2022-27949

A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (fo…

Fix: 2.3.1+
Fix from $1,950 2022-11-14
HTTP Server HIGH 7.5
CVE-2022-30556

Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the …

Fix: 2.4.54+
Fix from $1,950 2022-06-09
HTTP Server MEDIUM 5.3
CVE-2022-28614

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very larg…

Fix: after 2.4.53
Fix from $1,600 2022-06-09
Gobblin MEDIUM 5.5
CVE-2021-36151

In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. This affects versions <= 0.15.…

Fix: after 0.15.0
Fix from $1,600 2022-02-04
Shardingsphere Elasticjob Ui MEDIUM 6.5
CVE-2022-22733EPSS 38%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest acco…

Mitigation only
Fix from $1,600 2022-01-20