Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Superset MEDIUM 6.5
CVE-2024-24773

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apa…

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-02-28
Superset MEDIUM 6.5
CVE-2024-24779

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual dat…

Fix: 3.1.1+
Fix from $1,600 2024-02-28
Superset MEDIUM 5.4
CVE-2024-26016

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-02-28
Hertzbeat HIGH 7.5
CVE-2022-39337

Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat v…

Fix: 1.2.1+
Fix from $1,950 2023-12-22
Superset MEDIUM 6.5
CVE-2023-49734

An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the…

Fix: 2.1.2 / 3.0.2+
Fix from $1,600 2023-12-19
Doris HIGH 8.2
CVE-2023-41314

The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea…

Fix: 2.0.3+
Fix from $1,950 2023-12-18
Superset HIGH 8.8
CVE-2023-40610

Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database conn…

Fix: 2.1.2+
Fix from $1,950 2023-11-27
Superset MEDIUM 5.4
CVE-2023-36387

An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test d…

Fix: after 2.1.0
Fix from $1,600 2023-09-06
Pulsar MEDIUM 6.5
CVE-2023-37579

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, …

Fix: 2.10.4+
Fix from $1,600 2023-07-12
Airflow MEDIUM 6.5
CVE-2023-35908

Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommende…

Fix: 2.6.3+
Fix from $1,600 2023-07-12
Pulsar HIGH 8.8
CVE-2023-30429

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Whe…

Fix: 2.10.4+
Fix from $1,950 2023-07-12
Pulsar HIGH 8.1
CVE-2023-30428

Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP…

Fix: 2.10.4+
Fix from $1,950 2023-07-12
Iotdb Web Workbench CRITICAL 9.8
CVE-2023-30771

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotd…

Mitigation only
Fix from $2,300 2023-04-17
Iotdb HIGH 8.8
CVE-2023-24829

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 bef…

Fix: 0.13.3+
Fix from $1,950 2023-01-31
Shiro CRITICAL 9.8
CVE-2022-32532EPSS 26%

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatch…

Fix: 1.9.1+
Fix from $2,300 2022-06-29
Pulsar MEDIUM 6.5
CVE-2021-41571

In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API…

Fix: 2.6.4 / 2.7.3+
Fix from $1,600 2022-02-01
Kylin HIGH 7.5
CVE-2021-45457

In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and p…

Fix: 3.1.3+
Fix from $1,950 2022-01-06
Ozone MEDIUM 6.8
CVE-2021-39234

In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blo…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Druid MEDIUM 6.5
CVE-2021-36749EPSS 81%

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…

Fix: 0.22.0+
Fix from $1,600 2021-09-24
Tapestry HIGH 7.5
CVE-2021-30638EPSS 7%

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…

Fix: 5.6.4 / 5.7.2+
Fix from $1,950 2021-04-27
Solr CRITICAL 9.1
CVE-2021-29943EPSS 5%

When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests usi…

Fix: 8.8.2+
Fix from $2,300 2021-04-13
Hadoop HIGH 8.8
CVE-2020-9492

In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote UR…

Fix: after 3.2.1
Fix from $1,950 2021-01-26
Solr CRITICAL 9.8
CVE-2020-13957EPSS 79%

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote co…

Fix: after 8.6.2
Fix from $2,300 2020-10-13
Cxf CRITICAL 9.8
CVE-2019-12419EPSS 14%

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…

Fix: 3.2.11 / 3.3.4+
Fix from $2,300 2019-11-06
Mesos MEDIUM 6.5
CVE-2018-1000420

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …

Fix: after 0.17.1
Fix from $1,600 2019-01-09
Nifi HIGH 7.5
CVE-2018-17195

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…

Fix: after 1.7.1
Fix from $1,950 2018-12-19
Geode HIGH 8.8
CVE-2017-15695

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy cod…

Fix: after 1.4.0
Fix from $1,950 2018-06-13
Tomcat HIGH 7.5
CVE-2016-6797EPSS 8%

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.4…

Fix: after 8.5.4
Fix from $1,950 2017-08-10