Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HTTP Server MEDIUM 5.5
CVE-2020-13938EPSS 12%

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

Fix: 5.10.0+
Fix from $1,600 2021-06-10
Ignite CRITICAL 9.1
CVE-2020-1963

Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a fi…

Fix: after 2.8.0
Fix from $2,300 2020-06-03
Activemq MEDIUM 5.9
CVE-2019-0201EPSS 10%

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when…

Fix: 18.1.3.1.0 / 19.1.0.0.1+
Fix from $1,600 2019-05-23
Impala MEDIUM 6.5
CVE-2018-11785

Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running …

Fix: 3.0.1+
Fix from $1,600 2018-10-24
Sentry HIGH 8.8
CVE-2018-8028

An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker …

Fix: 2.0.1+
Fix from $1,950 2018-08-23
Zookeeper HIGH 7.5
CVE-2018-8012EPSS 8%

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-…

Fix: 3.4.10 / 19.1.0.0.1+
Fix from $1,950 2018-05-21
Ranger MEDIUM 5.9
CVE-2017-7677

In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for creat…

Fix: after 0.7.0
Fix from $1,600 2017-06-14