Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 MEDIUM 6.5 CVE-2026-26929 Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made wi… Airflow 3.1.8+ Fix from $1,6002026-03-17 HIGH 7.8 CVE-2025-27446 Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX… Apisix after 0.5 Fix from $1,9502025-07-06 MEDIUM 5.5 CVE-2024-29869 Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set exp… Hive 4.0.1+ Fix from $1,6002025-01-28 MEDIUM 5.5 CVE-2023-49582 Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, pot… Portable Runtime 1.7.5+ Fix from $1,6002024-08-26 HIGH 7.5 CVE-2023-50292 Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This iss… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 HIGH 7.5 CVE-2023-34981 A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP header… Tomcat Mitigation only Fix from $1,9502023-06-21 HIGH 7.5 CVE-2023-31453 Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro… Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 7.5 CVE-2023-31454 Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fro… Inlong after 1.6.0 Fix from $1,9502023-05-22 HIGH 8.1 CVE-2021-40331 An Incorrect Permission Assignment for Critical Resource vulnerability was found in the Apache Ranger Hive Plugin. Any user with SELECT privilege on … Ranger after 2.3.0 Fix from $1,9502023-05-05 HIGH 8.8 CVE-2022-37435 Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i… Shenyu Patch available Fix from $1,9502022-09-01 CRITICAL 9.1 CVE-2021-44521EPSS 55% When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab… Cassandra 3.0.26 / 3.11.12+ Fix from $2,3002022-02-11 MEDIUM 6.5 CVE-2021-39235 In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to… Ozone 1.2.0+ Fix from $1,6002021-11-19 MEDIUM 5.8 CVE-2020-17522 When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi… Traffic Control after 4.1.0 Fix from $1,6002021-01-26 HIGH 7.5 CVE-2019-10084 In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o… Impala after 3.2.0 Fix from $1,9502019-11-05 CRITICAL 9.8 CVE-2011-3923EPSS 88% Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. Struts 2.3.1.2+ Fix from $2,3002019-11-01 CRITICAL 9.8 CVE-2018-11792 In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER… Impala 3.0.1+ Fix from $2,3002018-10-24 HIGH 7.8 CVE-2017-3166 In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl… Hadoop Mitigation only Fix from $1,9502017-11-13 MEDIUM 6.5 CVE-2017-9792 In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt… Impala Mitigation only Fix from $1,6002017-10-04