Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thrift MEDIUM 6.5
CVE-2018-11798

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remo…

Fix: after 0.11.0
Fix from $1,600 2019-01-07
Karaf CRITICAL 9.8
CVE-2018-11788EPSS 7%

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …

Fix: 4.1.7+
Fix from $2,300 2019-01-07
Couchdb HIGH 7.2
CVE-2018-17188

Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilit…

Fix: 2.3.0+
Fix from $1,950 2019-01-02
Netbeans CRITICAL 9.8
CVE-2018-17191EPSS 8%

Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the n…

Mitigation only
Fix from $2,300 2018-12-31
Tika MEDIUM 6.5
CVE-2018-17197EPSS 6%

A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.

Fix: after 1.19.1
Fix from $1,600 2018-12-24
Oozie MEDIUM 6.5
CVE-2018-11799

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that result…

Fix: 5.1.0+
Fix from $1,600 2018-12-19
Nifi HIGH 7.5
CVE-2018-17194

When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE …

Fix: after 1.7.1
Fix from $1,950 2018-12-19
Nifi HIGH 7.5
CVE-2018-17195

The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack…

Fix: after 1.7.1
Fix from $1,950 2018-12-19
Nifi MEDIUM 6.5
CVE-2018-17192

The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers wou…

Fix: after 1.6.0
Fix from $1,600 2018-12-19
Nifi MEDIUM 6.1
CVE-2018-17193

The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attac…

Fix: after 1.7.1
Fix from $1,600 2018-12-19
Ofbiz HIGH 7.5
CVE-2018-8033EPSS 26%

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via …

Fix: after 16.11.04
Fix from $1,950 2018-12-13
Hadoop HIGH 8.8
CVE-2018-11766

In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary co…

Fix: after 2.7.6
Fix from $1,950 2018-11-27
Spark CRITICAL 9.8
CVE-2018-17190EPSS 9%

In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hos…

Mitigation only
Fix from $2,300 2018-11-19
Hadoop HIGH 8.8
CVE-2018-8009EPSS 8%

Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vu…

Fix: after 3.0.2
Fix from $1,950 2018-11-13
Qpid Proton J HIGH 7.4
CVE-2018-17187

The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a ve…

Fix: after 0.29.0
Fix from $1,950 2018-11-13
Hive HIGH 8.1
CVE-2018-11777

In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry …

Fix: after 3.1.0
Fix from $1,950 2018-11-08
Superset CRITICAL 9.8
CVE-2018-8021EPSS 53%

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. …

Fix: 0.23+
Fix from $2,300 2018-11-07
Syncope HIGH 7.2
CVE-2018-17186

An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file writ…

Fix: after 2.1.2
Fix from $1,950 2018-11-06
Syncope MEDIUM 5.4
CVE-2018-17184

A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report …

Fix: 2.0.11 / 2.1.2+
Fix from $1,600 2018-11-06
Tomcat Jk Connector HIGH 7.5
CVE-2018-11759EPSS 91%

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) …

Fix: after 1.2.44
Fix from $1,950 2018-10-31
Impala CRITICAL 9.8
CVE-2018-11792

In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER…

Fix: 3.0.1+
Fix from $2,300 2018-10-24
Impala MEDIUM 6.5
CVE-2018-11785

Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running …

Fix: 3.0.1+
Fix from $1,600 2018-10-24
Spark HIGH 7.5
CVE-2018-11804EPSS 6%

Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has be…

Fix: 2.2.3 / 2.3.3+
Fix from $1,950 2018-10-24
Activemq MEDIUM 6.1
CVE-2018-8006EPSS 57%

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apa…

Fix: after 5.15.5
Fix from $1,600 2018-10-10
Tika HIGH 7.5
CVE-2018-11796EPSS 7%

In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after eac…

Fix: after 1.19
Fix from $1,950 2018-10-09
Pdfbox MEDIUM 5.5
CVE-2018-11797

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing …

Fix: after 2.0.11
Fix from $1,600 2018-10-05
Ranger HIGH 8.8
CVE-2018-11778

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1…

Fix: 1.2.0+
Fix from $1,950 2018-10-05
Pony Mail MEDIUM 5.3
CVE-2017-5658

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead…

Fix: after 0.9
Fix from $1,600 2018-10-04
HTTP Server MEDIUM 5.9
CVE-2018-11763EPSS 51%

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time wit…

Fix: after 2.4.34
Fix from $1,600 2018-09-25
Couchdb HIGH 7.8
CVE-2018-14889

CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.

Mitigation only
Fix from $1,950 2018-09-21