Vulnerability index

Browse CVEs

207 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Dubbo CRITICAL 9.8
CVE-2023-46279

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the …

Mitigation only
Fix from $2,300 2023-12-15
Submarine CRITICAL 9.8
CVE-2023-46302

Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail…

Fix: 0.8.0+
Fix from $2,300 2023-11-20
Pyarrow CRITICAL 9.8
CVE-2023-47248EPSS 14%

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is …

Fix: after 14.0.0
Fix from $2,300 2023-11-09
Uimaj HIGH 8.8
CVE-2023-39913

Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apach…

Fix: 3.5.0+
Fix from $1,950 2023-11-08
Activemq CRITICAL 9.8
CVE-2023-46604 KEVEPSS 100%

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to…

Fix: 5.15.16 / 5.16.7+
Fix from $2,300 2023-10-27
Inlong HIGH 7.5
CVE-2023-46227

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.…

Fix: 1.9.0+
Fix from $1,950 2023-10-19
Avro HIGH 7.5
CVE-2023-39410

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of …

Fix: 1.11.3+
Fix from $1,950 2023-09-29
Superset MEDIUM 6.6
CVE-2023-37941EPSS 29%

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to …

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Airflow Spark Provider HIGH 8.8
CVE-2023-40195

Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflo…

Fix: 4.1.3+
Fix from $1,950 2023-08-28
Helix CRITICAL 9.8
CVE-2023-38647

An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.S…

Fix: 1.3.0+
Fix from $2,300 2023-07-26
Jackrabbit CRITICAL 9.8
CVE-2023-37895

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (in…

Fix: 2.20.11 / 2.21.18+
Fix from $2,300 2023-07-25
Inlong HIGH 7.5
CVE-2023-34434

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.…

Fix: after 1.7.0
Fix from $1,950 2023-07-25
Shardingsphere HIGH 8.8
CVE-2023-28754

Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a sp…

Fix: 5.4.0+
Fix from $1,950 2023-07-19
Eventmesh Connector Rabbitmq CRITICAL 9.8
CVE-2023-26512

CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac…

Fix: after 1.8.0
Fix from $2,300 2023-07-17
Johnzon MEDIUM 5.3
CVE-2023-33008

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache Johnzon. A malicious attacker can craft up some JSON input tha…

Fix: 1.2.21+
Fix from $1,600 2023-07-07
Nifi MEDIUM 6.5
CVE-2023-34212

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 all…

Fix: after 1.21.0
Fix from $1,600 2023-06-12
Inlong HIGH 7.5
CVE-2023-31058

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Linkis CRITICAL 9.8
CVE-2023-29215

In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC Eengi…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-29216

In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to co…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Inlong HIGH 8.8
CVE-2023-27296

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong,…

Fix: after 1.5.0
Fix from $1,950 2023-03-27
Log4j HIGH 7.5
CVE-2023-26464

** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or SocketAppender components with Log4j 1.x on JRE less than 1.7, an attacker that manages t…

Fix: 2.0+
Fix from $1,950 2023-03-10
Dubbo CRITICAL 9.8
CVE-2023-23638

A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.…

Fix: after 3.1.5
Fix from $2,300 2023-03-08
Kafka Connect HIGH 8.8
CVE-2023-25194EPSS 96%

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to…

Fix: after 3.3.2
Fix from $1,950 2023-02-07
Inlong CRITICAL 9.8
CVE-2023-24997

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.…

Fix: after 1.5.0
Fix from $2,300 2023-02-01
Linkis HIGH 8.8
CVE-2022-44645

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…

Fix: after 1.3.0
Fix from $1,950 2023-01-31
Dubbo CRITICAL 9.8
CVE-2021-32824

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…

Fix: 2.6.10 / 2.7.10+
Fix from $2,300 2023-01-03
Tapestry CRITICAL 9.8
CVE-2022-46366

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…

Fix: 4.0.0+
Fix from $2,300 2022-12-02
Sshd CRITICAL 9.8
CVE-2022-45047

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…

Fix: after 2.9.1
Fix from $2,300 2022-11-16
Jena Sdb CRITICAL 9.8
CVE-2022-45136

Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…

Fix: after 3.17.0
Fix from $2,300 2022-11-14
Linkis HIGH 8.8
CVE-2022-39944

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…

Fix: after 1.2.0
Fix from $1,950 2022-10-26