Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Karaf MEDIUM 6.5
CVE-2019-0191

Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …

Fix: 4.2.3+
Fix from $1,600 2019-03-21
Heron HIGH 7.5
CVE-2018-11789EPSS 7%

When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule …

Fix: after 0.17.8
Fix from $1,950 2019-03-21
Hadoop HIGH 8.8
CVE-2018-8009EPSS 8%

Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vu…

Fix: after 3.0.2
Fix from $1,950 2018-11-13
Tomcat Jk Connector HIGH 7.5
CVE-2018-11759EPSS 91%

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) …

Fix: after 1.2.44
Fix from $1,950 2018-10-31
Tika MEDIUM 5.9
CVE-2018-11762EPSS 5%

In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input …

Fix: after 1.18
Fix from $1,600 2018-09-19
Camel MEDIUM 5.3
CVE-2018-8041EPSS 10%

Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

Fix: after 2.21.1
Fix from $1,600 2018-09-17
Storm MEDIUM 5.5
CVE-2018-8008

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be ac…

Fix: after 1.2.1
Fix from $1,600 2018-06-05
Ambari MEDIUM 5.3
CVE-2018-8003

Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request whic…

Fix: after 2.6.1
Fix from $1,600 2018-05-03
Tomcat Jk Connector HIGH 7.5
CVE-2018-1323EPSS 47%

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-…

Fix: after 1.2.42
Fix from $1,950 2018-03-12
Ode HIGH 7.5
CVE-2018-1316

The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traver…

Fix: after 1.3.2
Fix from $1,950 2018-03-05
Oozie MEDIUM 6.5
CVE-2017-15712

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici…

Mitigation only
Fix from $1,600 2018-02-19
Allura HIGH 7.5
CVE-2018-1299

In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with A…

Fix: 1.8.0+
Fix from $1,950 2018-02-06
Storm HIGH 7.5
CVE-2014-0115EPSS 5%

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…

Patch available
Fix from $1,950 2017-10-30
Struts CRITICAL 9.8
CVE-2016-6795EPSS 8%

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…

Mitigation only
Fix from $2,300 2017-09-20
Solr HIGH 7.5
CVE-2017-3163EPSS 7%

When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file nam…

Fix: after 5.5.3
Fix from $1,950 2017-08-30
Tomcat HIGH 7.5
CVE-2017-7675EPSS 10%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory tr…

Mitigation only
Fix from $1,950 2017-08-11
Openmeetings MEDIUM 6.5
CVE-2016-0784EPSS 56%

Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated a…

Fix: after 3.1.0
Fix from $1,600 2016-04-11
Jetspeed HIGH 7.2
CVE-2016-0709EPSS 77%

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticate…

Fix: after 2.3.0
Fix from $1,950 2016-04-11
Activemq MEDIUM 5.0
CVE-2015-1830EPSS 84%

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows …

No fix yet
Fix from $1,600 2015-08-19
Myfaces MEDIUM 5.0
CVE-2011-4367EPSS 33%

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allo…

Fix: after 2.1.5
Fix from $1,600 2014-06-19
Couchdb MEDIUM 5.0
CVE-2012-5641EPSS 9%

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1…

Fix: after 2.3.2
Fix from $1,600 2014-03-18
Wicket MEDIUM 5.0
CVE-2012-1089EPSS 5%

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati…

Mitigation only
Fix from $1,600 2012-03-23
Openoffice HIGH 9.3
CVE-2010-3450EPSS 11%

Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…

Fix: 3.3.0+
Fix from $1,950 2011-01-28
Openoffice MEDIUM 6.9
CVE-2010-3689

soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privilege…

Fix: 3.3.0+
Fix from $1,600 2011-01-28
Shiro MEDIUM 5.0
CVE-2010-3863EPSS 55%

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows …

Fix: after 1.0.0
Fix from $1,600 2010-11-05
Tomcat MEDIUM 5.8
CVE-2009-2693EPSS 10%

Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbit…

Patch available
Fix from $1,600 2010-01-28
Tomcat MEDIUM 5.0
CVE-2008-5515EPSS 19%

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before f…

Patch available
Fix from $1,600 2009-06-16
Geronimo HIGH 9.4
CVE-2008-5518EPSS 36%

Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows all…

Patch available
Fix from $1,950 2009-04-17
Struts MEDIUM 5.0
CVE-2008-6505EPSS 73%

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary fil…

Mitigation only
Fix from $1,600 2009-03-23
Tomcat MEDIUM 5.0
CVE-2008-2370EPSS 53%

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization bef…

Patch available
Fix from $1,600 2008-08-04