Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Ofbiz MEDIUM 5.3
CVE-2024-23946

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $1,600 2024-02-29
Sling Servlets Resolver HIGH 7.5
CVE-2024-23673

Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli…

Fix: 2.11.0+
Fix from $1,950 2024-02-06
Shiro MEDIUM 6.5
CVE-2023-46749

Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe…

Fix: 1.13.0+
Fix from $1,600 2024-01-15
Tiles HIGH 7.5
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML…

Mitigation only
Fix from $1,950 2023-11-30
Shiro CRITICAL 9.8
CVE-2023-34478

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth…

Fix: 1.12.0+
Fix from $2,300 2023-07-24
Airflow MEDIUM 6.5
CVE-2023-22887

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Ofbiz HIGH 7.5
CVE-2022-47501EPSS 10%

Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. Thi…

Fix: 18.12.07+
Fix from $1,950 2023-04-14
Linkis CRITICAL 9.8
CVE-2023-27603

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Atlas HIGH 8.8
CVE-2022-34271

A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas ver…

Fix: after 2.2.0
Fix from $1,950 2022-12-14
Fineract HIGH 8.8
CVE-2022-44635EPSS 69%

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Ap…

Fix: 1.8.1+
Fix from $1,950 2022-11-29
Ivy HIGH 7.5
CVE-2022-37866

When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include pla…

Fix: 2.5.1+
Fix from $1,950 2022-11-07
Ivy CRITICAL 9.1
CVE-2022-37865

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip…

Fix: 2.5.1+
Fix from $2,300 2022-11-07
Uimaj HIGH 7.5
CVE-2022-32287

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files o…

Fix: after 3.3.0
Fix from $1,950 2022-11-03
Dolphinscheduler MEDIUM 6.5
CVE-2022-34662

When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade…

Fix: 3.0.0+
Fix from $1,600 2022-11-01
Dolphinscheduler MEDIUM 6.5
CVE-2022-26884

Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

Fix: 2.0.6+
Fix from $1,600 2022-10-28
Ofbiz CRITICAL 9.8
CVE-2022-25371

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in…

Fix: 18.12.06+
Fix from $2,300 2022-09-02
Hadoop HIGH 8.8
CVE-2021-33036

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…

Fix: 2.10.2 / 3.2.3+
Fix from $1,950 2022-06-15
Karaf MEDIUM 5.3
CVE-2022-22932

Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk…

Fix: 4.2.15 / 4.3.6+
Fix from $1,600 2022-01-26
James CRITICAL 9.1
CVE-2021-40525

Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ…

Fix: 3.6.2+
Fix from $2,300 2022-01-04
Solr CRITICAL 9.8
CVE-2021-44548EPSS 5%

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…

Fix: 8.11.1+
Fix from $2,300 2021-12-23
HTTP Server CRITICAL 9.8
CVE-2021-42013 KEVEPSS 100%

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs…

Fix: 9.2.6.0 / 18.1.0.1.0+
Fix from $2,300 2021-10-07
HTTP Server CRITICAL 9.8
CVE-2021-41773 KEVEPSS 100%

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi…

Patch available
Fix from $2,300 2021-10-05
Servicecomb HIGH 7.5
CVE-2021-21501

Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0.

Fix: 2.0.0+
Fix from $1,950 2021-08-10
Ambari HIGH 7.5
CVE-2020-13924

In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to …

Fix: after 2.6.2.2
Fix from $1,950 2021-03-17
Asterixdb MEDIUM 5.5
CVE-2020-9479

When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache A…

Fix: 0.9.5+
Fix from $1,600 2021-03-01
Flink HIGH 7.5
CVE-2020-17518EPSS 50%

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a m…

Fix: 1.11.3+
Fix from $1,950 2021-01-05
Rocketmq MEDIUM 5.3
CVE-2019-17572

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020…

Fix: after 4.6.0
Fix from $1,600 2020-05-14
Tapestry HIGH 7.5
CVE-2019-0207

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the chara…

Fix: after 5.4.4
Fix from $1,950 2019-09-16
Camel HIGH 7.5
CVE-2019-0194EPSS 8%

Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and ea…

Fix: after 2.22.2
Fix from $1,950 2019-04-30
Jspwiki HIGH 7.5
CVE-2019-0225EPSS 10%

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could b…

Fix: 2.11.0+
Fix from $1,950 2019-03-28