Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2020-17523EPSS 86% Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.1+ Fix from $2,3002021-02-03 HIGH 7.5 CVE-2021-26117EPSS 11% The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior… Activemq 2.16.0 / 5.15.14+ Fix from $1,9502021-01-27 CRITICAL 9.8 CVE-2020-17510EPSS 9% Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. Shiro 1.7.0+ Fix from $2,3002020-11-05 HIGH 7.5 CVE-2018-11765EPSS 5% In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe… Hadoop after 2.9.2 Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2019-12405 Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.… Traffic Control Mitigation only Fix from $2,3002019-09-09 HIGH 8.8 CVE-2018-1317 In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as other users without authentica… Zeppelin 0.8.0+ Fix from $1,9502019-04-23 HIGH 8.1 CVE-2018-11787 In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re… Karaf 3.0.9 / 4.0.9+ Fix from $1,9502018-09-18 MEDIUM 6.8 CVE-2017-12610 In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol mess… Kafka after 0.11.0.1 Fix from $1,6002018-07-26 CRITICAL 9.8 CVE-2018-1312EPSS 16% In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g… HTTP Server Mitigation only Fix from $2,3002018-03-26 MEDIUM 6.5 CVE-2018-1286 In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi… Openmeetings after 4.0.1 Fix from $1,6002018-02-28 HIGH 7.5 CVE-2017-5635 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originatin… Nifi Mitigation only Fix from $1,9502017-10-19 HIGH 7.5 CVE-2017-9803 Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a… Solr Mitigation only Fix from $1,9502017-09-18 CRITICAL 9.8 CVE-2016-4460EPSS 6% Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication. Pony Mail Patch available Fix from $2,3002017-08-22 CRITICAL 9.8 CVE-2012-0803 The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa… Cxf Patch available Fix from $2,3002017-08-08 CRITICAL 9.8 CVE-2017-5640 It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski… Impala Mitigation only Fix from $2,3002017-07-10 HIGH 7.5 CVE-2017-7660EPSS 6% Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node… Solr Mitigation only Fix from $1,9502017-07-07 CRITICAL 9.8 CVE-2017-3167EPSS 20% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p… HTTP Server 2.2.33 / 2.4.26+ Fix from $2,3002017-06-20 MEDIUM 6.5 CVE-2016-3085 Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl… Cloudstack No fix yet Fix from $1,6002016-06-10 CRITICAL 9.1 CVE-2016-4432EPSS 8% The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons… Qpid Broker J 6.0.3+ Fix from $2,3002016-06-01 MEDIUM 5.9 CVE-2016-3094EPSS 8% PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a… Qpid Broker J after 6.0.2 Fix from $1,6002016-06-01 CRITICAL 9.8 CVE-2016-0733 The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to by… Ranger after 0.5.0 Fix from $2,3002016-04-12 HIGH 8.3 CVE-2015-7521EPSS 6% The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, … Hive No fix yet Fix from $1,9502016-01-29 HIGH 7.3 CVE-2015-1772EPSS 7% The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.… Hive Mitigation only Fix from $1,9502015-12-21 HIGH 7.5 CVE-2014-3612EPSS 7% The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att… Activemq Mitigation only Fix from $1,9502015-08-24 MEDIUM 5.0 CVE-2014-7807 Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, … Cloudstack Mitigation only Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-3623EPSS 9% Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does … Wss4j 1.6.17 / 2.0.2+ Fix from $1,6002014-10-30 HIGH 7.5 CVE-2014-0074EPSS 5% Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e… Shiro No fix yet Fix from $1,9502014-10-06 MEDIUM 5.0 CVE-2013-2756EPSS 6% Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa… Cloudstack Patch available Fix from $1,6002014-05-23 MEDIUM 6.8 CVE-2013-2067EPSS 7% java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor… Tomcat Patch available Fix from $1,6002013-06-01 MEDIUM 6.4 CVE-2013-3060EPSS 6% The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau… Activemq after 5.7.0 Fix from $1,6002013-04-21