Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Airflow HIGH 7.8
CVE-2022-41131

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf…

Fix: 2.3.0 / 4.1.0+
Fix from $1,950 2022-11-22
Airflow MEDIUM 5.5
CVE-2022-40954

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $1,600 2022-11-22
Airflow CRITICAL 9.8
CVE-2022-38649

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Hama HIGH 7.5
CVE-2022-45470

missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect t…

Fix: after 1.7.1
Fix from $1,950 2022-11-21
Sshd CRITICAL 9.8
CVE-2022-45047

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized j…

Fix: after 2.9.1
Fix from $2,300 2022-11-16
Archiva HIGH 7.5
CVE-2022-40308

If anonymous read enabled, it's possible to read the database file directly without logging in.

Fix: 2.2.9+
Fix from $1,950 2022-11-15
Airflow MEDIUM 6.1
CVE-2022-45402EPSS 82%

In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

Fix: 2.4.3+
Fix from $1,600 2022-11-15
Jena Sdb CRITICAL 9.8
CVE-2022-45136

Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the u…

Fix: after 3.17.0
Fix from $2,300 2022-11-14
Soap CRITICAL 9.8
CVE-2022-45378

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok…

Fix: after 2.3
Fix from $2,300 2022-11-14
Airflow HIGH 8.8
CVE-2022-40127EPSS 86%

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually …

Fix: 2.4.0+
Fix from $1,950 2022-11-14
Airflow HIGH 7.5
CVE-2022-27949

A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (fo…

Fix: 2.3.1+
Fix from $1,950 2022-11-14
Ivy HIGH 7.5
CVE-2022-37866

When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include pla…

Fix: 2.5.1+
Fix from $1,950 2022-11-07
Commons Bcel CRITICAL 9.8
CVE-2022-42920

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds wri…

Fix: 6.6.0+
Fix from $2,300 2022-11-07
Ivy CRITICAL 9.1
CVE-2022-37865

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip…

Fix: 2.5.1+
Fix from $2,300 2022-11-07
Pulsar HIGH 8.1
CVE-2022-33684

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllo…

Fix: 2.7.5 / 2.8.4+
Fix from $1,950 2022-11-04
Uimaj HIGH 7.5
CVE-2022-32287

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files o…

Fix: after 3.3.0
Fix from $1,950 2022-11-03
Sling Cms MEDIUM 5.4
CVE-2022-43670

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and pri…

Fix: after 1.1.0
Fix from $1,600 2022-11-02
Airflow MEDIUM 6.1
CVE-2022-43982

In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.

Fix: 2.4.2+
Fix from $1,600 2022-11-02
Airflow MEDIUM 6.1
CVE-2022-43985

In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.

Fix: 2.4.2+
Fix from $1,600 2022-11-02
Dolphinscheduler MEDIUM 6.5
CVE-2022-34662

When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade…

Fix: 3.0.0+
Fix from $1,600 2022-11-01
Spark MEDIUM 5.4
CVE-2022-31777

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScri…

Fix: 3.2.2+
Fix from $1,600 2022-11-01
Tomcat HIGH 7.5
CVE-2022-42252

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via s…

Fix: 8.5.83 / 9.0.68+
Fix from $1,950 2022-11-01
Dolphinscheduler MEDIUM 6.5
CVE-2022-26884

Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

Fix: 2.0.6+
Fix from $1,600 2022-10-28
Flume CRITICAL 9.8
CVE-2022-42468

Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsa…

Fix: after 1.10.1
Fix from $2,300 2022-10-26
Linkis HIGH 8.8
CVE-2022-39944

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when…

Fix: after 1.2.0
Fix from $1,950 2022-10-26
Iotdb HIGH 7.5
CVE-2022-43766

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP que…

Fix: after 0.13.2
Fix from $1,950 2022-10-26
Batik HIGH 7.5
CVE-2022-41704

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics pri…

Fix: 1.16+
Fix from $1,950 2022-10-25
Batik HIGH 7.5
CVE-2022-42890

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML …

Fix: 1.16+
Fix from $1,950 2022-10-25
Geode MEDIUM 5.4
CVE-2022-34870

Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region …

Fix: after 1.15.0
Fix from $1,600 2022-10-25
Heron CRITICAL 9.8
CVE-2021-42010

Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-…

Fix: 0.20.5-incubating+
Fix from $2,300 2022-10-24