Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Shiro CRITICAL 9.8
CVE-2020-17523EPSS 86%

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.1+
Fix from $2,300 2021-02-03
Activemq HIGH 7.5
CVE-2021-26117EPSS 11%

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior…

Fix: 2.16.0 / 5.15.14+
Fix from $1,950 2021-01-27
Shiro CRITICAL 9.8
CVE-2020-17510EPSS 9%

Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.7.0+
Fix from $2,300 2020-11-05
Hadoop HIGH 7.5
CVE-2018-11765EPSS 5%

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe…

Fix: after 2.9.2
Fix from $1,950 2020-09-30
Traffic Control CRITICAL 9.8
CVE-2019-12405

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…

Mitigation only
Fix from $2,300 2019-09-09
Zeppelin HIGH 8.8
CVE-2018-1317

In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica…

Fix: 0.8.0+
Fix from $1,950 2019-04-23
Karaf HIGH 8.1
CVE-2018-11787

In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…

Fix: 3.0.9 / 4.0.9+
Fix from $1,950 2018-09-18
Kafka MEDIUM 6.8
CVE-2017-12610

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol mess…

Fix: after 0.11.0.1
Fix from $1,600 2018-07-26
HTTP Server CRITICAL 9.8
CVE-2018-1312EPSS 16%

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…

Mitigation only
Fix from $2,300 2018-03-26
Openmeetings MEDIUM 6.5
CVE-2018-1286

In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi…

Fix: after 4.0.1
Fix from $1,600 2018-02-28
Nifi HIGH 7.5
CVE-2017-5635

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin…

Mitigation only
Fix from $1,950 2017-10-19
Solr HIGH 7.5
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a…

Mitigation only
Fix from $1,950 2017-09-18
Pony Mail CRITICAL 9.8
CVE-2016-4460EPSS 6%

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

Patch available
Fix from $2,300 2017-08-22
Cxf CRITICAL 9.8
CVE-2012-0803

The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa…

Patch available
Fix from $2,300 2017-08-08
Impala CRITICAL 9.8
CVE-2017-5640

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski…

Mitigation only
Fix from $2,300 2017-07-10
Solr HIGH 7.5
CVE-2017-7660EPSS 6%

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node…

Mitigation only
Fix from $1,950 2017-07-07
HTTP Server CRITICAL 9.8
CVE-2017-3167EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
Cloudstack MEDIUM 6.5
CVE-2016-3085

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…

No fix yet
Fix from $1,600 2016-06-10
Qpid Broker J CRITICAL 9.1
CVE-2016-4432EPSS 8%

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…

Fix: 6.0.3+
Fix from $2,300 2016-06-01
Qpid Broker J MEDIUM 5.9
CVE-2016-3094EPSS 8%

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…

Fix: after 6.0.2
Fix from $1,600 2016-06-01
Ranger CRITICAL 9.8
CVE-2016-0733

The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by…

Fix: after 0.5.0
Fix from $2,300 2016-04-12
Hive HIGH 8.3
CVE-2015-7521EPSS 6%

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …

No fix yet
Fix from $1,950 2016-01-29
Hive HIGH 7.3
CVE-2015-1772EPSS 7%

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…

Mitigation only
Fix from $1,950 2015-12-21
Activemq HIGH 7.5
CVE-2014-3612EPSS 7%

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…

Mitigation only
Fix from $1,950 2015-08-24
Cloudstack MEDIUM 5.0
CVE-2014-7807

Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …

Mitigation only
Fix from $1,600 2014-12-10
Wss4j MEDIUM 5.0
CVE-2014-3623EPSS 9%

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does …

Fix: 1.6.17 / 2.0.2+
Fix from $1,600 2014-10-30
Shiro HIGH 7.5
CVE-2014-0074EPSS 5%

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…

No fix yet
Fix from $1,950 2014-10-06
Cloudstack MEDIUM 5.0
CVE-2013-2756EPSS 6%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa…

Patch available
Fix from $1,600 2014-05-23
Tomcat MEDIUM 6.8
CVE-2013-2067EPSS 7%

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor…

Patch available
Fix from $1,600 2013-06-01
Activemq MEDIUM 6.4
CVE-2013-3060EPSS 6%

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau…

Fix: after 5.7.0
Fix from $1,600 2013-04-21