Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
MEDIUM 5.3 CVE-2024-23946 Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $1,6002024-02-29 HIGH 7.5 CVE-2024-23673 Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sli… Sling Servlets Resolver 2.11.0+ Fix from $1,9502024-02-06 MEDIUM 6.5 CVE-2023-46749 Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe… Shiro 1.13.0+ Fix from $1,6002024-01-15 HIGH 7.5 CVE-2023-49735 ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML… Tiles Mitigation only Fix from $1,9502023-11-30 CRITICAL 9.8 CVE-2023-34478 Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used togeth… Shiro 1.12.0+ Fix from $2,3002023-07-24 MEDIUM 6.5 CVE-2023-22887 Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intende… Airflow 2.6.3+ Fix from $1,6002023-07-12 HIGH 7.5 CVE-2022-47501EPSS 10% Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  pre-authentication attack. Thi… Ofbiz 18.12.07+ Fix from $1,9502023-04-14 CRITICAL 9.8 CVE-2023-27603 In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead… Linkis after 1.3.1 Fix from $2,3002023-04-10 HIGH 8.8 CVE-2022-34271 A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas ver… Atlas after 2.2.0 Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-44635EPSS 69% Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Ap… Fineract 1.8.1+ Fix from $1,9502022-11-29 HIGH 7.5 CVE-2022-37866 When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include pla… Ivy 2.5.1+ Fix from $1,9502022-11-07 CRITICAL 9.1 CVE-2022-37865 With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip… Ivy 2.5.1+ Fix from $2,3002022-11-07 HIGH 7.5 CVE-2022-32287 A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files o… Uimaj after 3.3.0 Fix from $1,9502022-11-03 MEDIUM 6.5 CVE-2022-34662 When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade… Dolphinscheduler 3.0.0+ Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-26884 Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. Dolphinscheduler 2.0.6+ Fix from $1,6002022-10-28 CRITICAL 9.8 CVE-2022-25371 Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in… Ofbiz 18.12.06+ Fix from $2,3002022-09-02 HIGH 8.8 CVE-2021-33036 In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar… Hadoop 2.10.2 / 3.2.3+ Fix from $1,9502022-06-15 MEDIUM 5.3 CVE-2022-22932 Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk… Karaf 4.2.15 / 4.3.6+ Fix from $1,6002022-01-26 CRITICAL 9.1 CVE-2021-40525 Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writ… James 3.6.2+ Fix from $2,3002022-01-04 CRITICAL 9.8 CVE-2021-44548EPSS 5% An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n… Solr 8.11.1+ Fix from $2,3002021-12-23 CRITICAL 9.8 CVE-2021-42013 KEVEPSS 100% It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs… HTTP Server 9.2.6.0 / 18.1.0.1.0+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-41773 KEVEPSS 100% A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to fi… HTTP Server Patch available Fix from $2,3002021-10-05 HIGH 7.5 CVE-2021-21501 Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0. Servicecomb 2.0.0+ Fix from $1,9502021-08-10 HIGH 7.5 CVE-2020-13924 In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to … Ambari after 2.6.2.2 Fix from $1,9502021-03-17 MEDIUM 5.5 CVE-2020-9479 When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache A… Asterixdb 0.9.5+ Fix from $1,6002021-03-01 HIGH 7.5 CVE-2020-17518EPSS 50% Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a m… Flink 1.11.3+ Fix from $1,9502021-01-05 MEDIUM 5.3 CVE-2019-17572 In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020… Rocketmq after 4.6.0 Fix from $1,6002020-05-14 HIGH 7.5 CVE-2019-0207 Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the chara… Tapestry after 5.4.4 Fix from $1,9502019-09-16 HIGH 7.5 CVE-2019-0194EPSS 8% Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and ea… Camel after 2.22.2 Fix from $1,9502019-04-30 HIGH 7.5 CVE-2019-0225EPSS 10% A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could b… Jspwiki 2.11.0+ Fix from $1,9502019-03-28