Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Airflow MEDIUM 6.5
CVE-2026-26929

Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made wi…

Fix: 3.1.8+
Fix from $1,600 2026-03-17
Apisix HIGH 7.8
CVE-2025-27446

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX…

Fix: after 0.5
Fix from $1,950 2025-07-06
Hive MEDIUM 5.5
CVE-2024-29869

Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set exp…

Fix: 4.0.1+
Fix from $1,600 2025-01-28
Portable Runtime MEDIUM 5.5
CVE-2023-49582

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pot…

Fix: 1.7.5+
Fix from $1,600 2024-08-26
Solr HIGH 7.5
CVE-2023-50292

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This iss…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Tomcat HIGH 7.5
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header…

Mitigation only
Fix from $1,950 2023-06-21
Inlong HIGH 7.5
CVE-2023-31453

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Inlong HIGH 7.5
CVE-2023-31454

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro…

Fix: after 1.6.0
Fix from $1,950 2023-05-22
Ranger HIGH 8.1
CVE-2021-40331

An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on …

Fix: after 2.3.0
Fix from $1,950 2023-05-05
Shenyu HIGH 8.8
CVE-2022-37435

Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i…

Patch available
Fix from $1,950 2022-09-01
Cassandra CRITICAL 9.1
CVE-2021-44521EPSS 55%

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…

Fix: 3.0.26 / 3.11.12+
Fix from $2,300 2022-02-11
Ozone MEDIUM 6.5
CVE-2021-39235

In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Traffic Control MEDIUM 5.8
CVE-2020-17522

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi…

Fix: after 4.1.0
Fix from $1,600 2021-01-26
Impala HIGH 7.5
CVE-2019-10084

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o…

Fix: after 3.2.0
Fix from $1,950 2019-11-05
Struts CRITICAL 9.8
CVE-2011-3923EPSS 88%

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

Fix: 2.3.1.2+
Fix from $2,300 2019-11-01
Impala CRITICAL 9.8
CVE-2018-11792

In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER…

Fix: 3.0.1+
Fix from $2,300 2018-10-24
Hadoop HIGH 7.8
CVE-2017-3166

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl…

Mitigation only
Fix from $1,950 2017-11-13
Impala MEDIUM 6.5
CVE-2017-9792

In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt…

Mitigation only
Fix from $1,600 2017-10-04