Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nifi HIGH 7.5
CVE-2020-9487

In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to c…

Fix: after 1.11.4
Fix from $1,950 2020-10-01
Nifi HIGH 7.5
CVE-2020-9491

In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors …

Fix: after 1.11.4
Fix from $1,950 2020-10-01
Ant HIGH 7.5
CVE-2020-11979EPSS 8%

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to …

Fix: 6.8.0+
Fix from $1,950 2020-10-01
Nifi MEDIUM 5.5
CVE-2020-13940

In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini…

Fix: after 1.11.4
Fix from $1,600 2020-10-01
Superset HIGH 8.1
CVE-2020-13952

In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines …

Fix: 0.37.2+
Fix from $1,950 2020-09-30
Openmeetings HIGH 7.5
CVE-2020-13951EPSS 70%

Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

Fix: after 5.0.0
Fix from $1,950 2020-09-30
Tapestry MEDIUM 5.3
CVE-2020-13953

In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

Fix: 5.6.4 / 5.7.2+
Fix from $1,600 2020-09-30
Hadoop HIGH 7.5
CVE-2018-11765EPSS 5%

In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerbe…

Fix: after 2.9.2
Fix from $1,950 2020-09-30
Airflow MEDIUM 6.1
CVE-2020-13944EPSS 25%

In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.

Fix: 1.10.15 / 2.0.2+
Fix from $1,600 2020-09-17
Superset HIGH 8.8
CVE-2020-13948

While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text…

Fix: 0.37.1+
Fix from $1,950 2020-09-17
Atlas MEDIUM 6.1
CVE-2020-13928

Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of th…

Fix: 2.1.0+
Fix from $1,600 2020-09-16
Syncope HIGH 7.2
CVE-2020-11977

In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Se…

Fix: 2.1.7+
Fix from $1,950 2020-09-15
Struts CRITICAL 9.8
CVE-2019-0230EPSS 97%

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Fix: after 8.0.23
Fix from $2,300 2020-09-14
Struts HIGH 7.5
CVE-2019-0233EPSS 68%

An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

Fix: after 8.0.23
Fix from $1,950 2020-09-14
Cocoon HIGH 7.5
CVE-2020-11991EPSS 72%

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc…

Fix: after 2.1.12
Fix from $1,950 2020-09-11
Activemq CRITICAL 9.8
CVE-2020-11998EPSS 51%

A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map …

Fix: after 8.5.0
Fix from $2,300 2020-09-10
Activemq MEDIUM 5.9
CVE-2020-13920

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to con…

Fix: 5.15.12+
Fix from $1,600 2020-09-10
Netbeans CRITICAL 9.8
CVE-2020-11986EPSS 10%

To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build…

Fix: after 12.0
Fix from $2,300 2020-09-09
Cassandra MEDIUM 5.9
CVE-2020-13946

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Ap…

Fix: 2.1.22 / 2.2.18+
Fix from $1,600 2020-09-01
Shiro HIGH 7.5
CVE-2020-13933EPSS 48%

Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

Fix: 1.6.0+
Fix from $1,950 2020-08-17
Solr HIGH 8.8
CVE-2020-13941

Reported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released in Solr version 8.6.0. The Replication handler (https://lucene.apache.org…

Fix: 8.6.0+
Fix from $1,950 2020-08-17
Fortress HIGH 7.5
CVE-2020-11976

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive in…

Fix: 7.17.0 / 8.9.0+
Fix from $1,950 2020-08-11
HTTP Server HIGH 7.5
CVE-2020-9490EPSS 90%

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash whe…

Fix: 2.4.46+
Fix from $1,950 2020-08-07
HTTP Server CRITICAL 9.8
CVE-2020-11984EPSS 90%

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

Fix: after 8.2.2
Fix from $2,300 2020-08-07
HTTP Server HIGH 7.5
CVE-2020-11993EPSS 59%

Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging stateme…

Fix: 2.4.44+
Fix from $1,950 2020-08-07
HTTP Server MEDIUM 5.3
CVE-2020-11985EPSS 7%

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rule…

Fix: after 2.4.23
Fix from $1,600 2020-08-07
Skywalking CRITICAL 9.8
CVE-2020-13921EPSS 33%

**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

Patch available
Fix from $2,300 2020-08-05
Artemis MEDIUM 6.1
CVE-2020-13932

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vuln…

Fix: after 2.13.0
Fix from $1,600 2020-07-20
Airflow MEDIUM 6.1
CVE-2020-9485

An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.

Fix: after 1.10.10
Fix from $1,600 2020-07-17
Airflow CRITICAL 9.8
CVE-2020-11981EPSS 37%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…

Fix: after 1.10.10
Fix from $2,300 2020-07-17