Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Guacamole MEDIUM 6.5
CVE-2021-41767

Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses. This may allo…

Fix: after 1.3.0
Fix from $1,600 2022-01-11
Nifi MEDIUM 6.5
CVE-2021-44145

In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious externa…

Fix: 1.15.1+
Fix from $1,600 2021-12-17
Ozone MEDIUM 5.3
CVE-2021-41532

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Santuario Xml Security For Java HIGH 7.5
CVE-2021-40690EPSS 7%

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is…

Fix: 2.1.7 / 2.2.3+
Fix from $1,950 2021-09-19
Airflow MEDIUM 5.3
CVE-2021-35936

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…

Fix: 2.1.2+
Fix from $1,600 2021-08-16
Wicket HIGH 7.5
CVE-2021-23937

A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups fro…

Fix: after 9.2.0
Fix from $1,950 2021-05-25
Tapestry HIGH 7.5
CVE-2021-30638EPSS 7%

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…

Fix: 5.6.4 / 5.7.2+
Fix from $1,950 2021-04-27
Tapestry CRITICAL 9.8
CVE-2021-27850EPSS 94%

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5,…

Fix: 5.6.2 / 5.7.1+
Fix from $2,300 2021-04-15
Tomcat HIGH 7.5
CVE-2021-25122EPSS 18%

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate re…

Fix: 21.3.0+
Fix from $1,950 2021-03-01
Tomcat MEDIUM 5.9
CVE-2021-24122EPSS 23%

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 t…

Fix: after 9.0.39
Fix from $1,600 2021-01-14
Tomcat HIGH 7.5
CVE-2020-17527EPSS 25%

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTT…

Fix: 21.1.2+
Fix from $1,950 2020-12-03
Superset MEDIUM 5.3
CVE-2019-12414

In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

Fix: 0.32+
Fix from $1,600 2019-12-16
Nifi MEDIUM 5.3
CVE-2019-10083

When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most …

Fix: after 1.9.2
Fix from $1,600 2019-11-19
Storm HIGH 7.5
CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…

Fix: after 1.2.2
Fix from $1,950 2019-07-26
Traffic Server HIGH 7.5
CVE-2018-11783

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plug…

Fix: after 8.0.1
Fix from $1,950 2019-03-07
Hadoop HIGH 7.5
CVE-2018-1296

In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs,…

Fix: after 2.7.5
Fix from $1,950 2019-02-07
Ofbiz HIGH 7.5
CVE-2018-8033EPSS 26%

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via …

Fix: after 16.11.04
Fix from $1,950 2018-12-13
Pony Mail MEDIUM 5.3
CVE-2017-5658

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead…

Fix: after 0.9
Fix from $1,600 2018-10-04
Mesos MEDIUM 5.9
CVE-2018-8023

Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2…

Fix: 1.4.2+
Fix from $1,600 2018-09-21
Spark MEDIUM 5.4
CVE-2018-8024EPSS 5%

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's j…

Fix: after 2.2.1
Fix from $1,600 2018-07-12
Directory Ldap Api CRITICAL 9.8
CVE-2018-1337EPSS 5%

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before…

Fix: 1.0.2+
Fix from $2,300 2018-07-10
Pluto HIGH 7.5
CVE-2018-1306EPSS 44%

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i…

No fix yet
Fix from $1,950 2018-06-27
Mxnet MEDIUM 6.5
CVE-2018-1281

The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_…

Fix: 1.0.0+
Fix from $1,600 2018-06-08
Storm MEDIUM 6.5
CVE-2018-1332

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonat…

Fix: after 1.2.1
Fix from $1,600 2018-06-05
Openoffice HIGH 7.5
CVE-2018-10583EPSS 79%

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co…

No fix yet
Fix from $1,950 2018-05-01
Tomcat Jk Connector HIGH 7.5
CVE-2018-1323EPSS 47%

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-…

Fix: after 1.2.42
Fix from $1,950 2018-03-12
Geode HIGH 7.5
CVE-2017-15696

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req…

Fix: after 1.3.0
Fix from $1,950 2018-02-26
Hadoop MEDIUM 6.5
CVE-2017-15713

Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose priv…

Fix: after 2.8.2
Fix from $1,600 2018-01-19
Geode HIGH 7.5
CVE-2017-9795

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…

Fix: 1.3.0+
Fix from $1,950 2018-01-10
Geode HIGH 7.1
CVE-2017-12622

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with…

Fix: 1.3.0+
Fix from $1,950 2018-01-10