Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Airflow MEDIUM 6.5
CVE-2026-68969

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Ranger MEDIUM 6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $4,000 2026-08-10
Apache Airflow Providers Opensearch MEDIUM 6.5
CVE-2026-43826

The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920…

Fix: 1.9.1+
Fix from $1,600 2026-05-11
Apache Airflow Providers Elasticsearch MEDIUM 6.5
CVE-2026-41018

The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:…

Fix: 6.5.3+
Fix from $1,600 2026-05-11
Airflow HIGH 7.5
CVE-2026-31987

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that…

Fix: 3.2.0+
Fix from $1,950 2026-04-16
Airflow HIGH 7.5
CVE-2025-66236

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to …

Fix: 3.2.0+
Fix from $1,950 2026-04-13
Tomcat HIGH 7.5
CVE-2026-34487

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet…

Fix: 9.0.117 / 10.1.54+
Fix from $1,950 2026-04-09
Cassandra MEDIUM 5.5
CVE-2026-27315

Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh co…

Fix: 4.0.20+
Fix from $1,600 2026-04-07
Zookeeper HIGH 7.5
CVE-2026-24308

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive inf…

Fix: 3.8.6 / 3.9.5+
Fix from $1,950 2026-03-07
Airflow MEDIUM 6.5
CVE-2025-27555

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Linkis MEDIUM 6.5
CVE-2025-59355

A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter s…

Fix: 1.8.0+
Fix from $1,600 2026-01-19
Airflow HIGH 7.5
CVE-2025-68675

In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authe…

Fix: 3.1.6+
Fix from $1,950 2026-01-16
Apisix HIGH 7.5
CVE-2025-62232

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…

Fix: 3.14.0+
Fix from $1,950 2025-10-31
Iotdb HIGH 7.5
CVE-2025-26864

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of…

Fix: 1.3.4+
Fix from $1,950 2025-05-14
Iotdb HIGH 7.5
CVE-2025-26795

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive…

Fix: 1.3.4 / 2.0.2+
Fix from $1,950 2025-05-14
Artemis MEDIUM 6.5
CVE-2025-27391

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th…

Fix: 2.40.0+
Fix from $1,600 2025-04-09
Pulsar MEDIUM 6.5
CVE-2025-30677

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka …

Fix: 3.0.11 / 3.3.6+
Fix from $1,600 2025-04-09
Arrow HIGH 7.5
CVE-2024-41178

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using…

Fix: after 0.10.1
Fix from $1,950 2024-07-23
Solr Operator MEDIUM 6.5
CVE-2024-31391

Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Opera…

Fix: 0.8.1+
Fix from $1,600 2024-04-12
Linkis MEDIUM 5.3
CVE-2023-50740

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users …

Fix: 1.5.0+
Fix from $1,600 2024-03-06
Airflow MEDIUM 6.5
CVE-2023-51702

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes th…

Fix: 2.6.1 / 7.0.0+
Fix from $1,600 2024-01-24
Airflow HIGH 7.5
CVE-2023-46215

Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as cl…

Fix: 2.7.0+
Fix from $1,950 2023-10-28
Santuario Xml Security For Java MEDIUM 6.5
CVE-2023-44483

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue whe…

Fix: 2.2.6 / 2.3.4+
Fix from $1,600 2023-10-20
Geode HIGH 7.5
CVE-2021-34797

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with …

Fix: after 1.13.4
Fix from $1,950 2022-01-04
Impala HIGH 7.5
CVE-2021-28131

Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala lo…

Fix: 4.0.0+
Fix from $1,950 2021-07-22
Nifi HIGH 7.5
CVE-2020-9486

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was tr…

Fix: after 1.11.4
Fix from $1,950 2020-10-01
Nifi HIGH 7.5
CVE-2020-1942

In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the …

Fix: after 1.11.0
Fix from $1,950 2020-02-11
Nifi MEDIUM 5.3
CVE-2020-1928

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose…

Mitigation only
Fix from $1,600 2020-01-28
Impala HIGH 7.5
CVE-2019-10084

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o…

Fix: after 3.2.0
Fix from $1,950 2019-11-05
Storm HIGH 7.5
CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…

Fix: after 1.2.2
Fix from $1,950 2019-07-26