Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kafka MEDIUM 6.8
CVE-2017-12610

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol mess…

Fix: after 0.11.0.1
Fix from $1,600 2018-07-26
Kafka MEDIUM 5.4
CVE-2018-1288

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for …

Fix: 18.1.2.1.0+
Fix from $1,600 2018-07-26
Tomee MEDIUM 6.1
CVE-2018-8031

The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. Thi…

Fix: 7.0.5+
Fix from $1,600 2018-07-23
Openwhisk CRITICAL 9.8
CVE-2018-11756EPSS 8%

In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1…

Fix: 1.0.1 / 1.0.2+
Fix from $2,300 2018-07-23
Openwhisk CRITICAL 9.8
CVE-2018-11757EPSS 7%

In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an a…

Fix: after 1.3.0
Fix from $2,300 2018-07-23
Ignite CRITICAL 9.8
CVE-2018-8018EPSS 7%

In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deseriali…

Fix: 2.4.8 / 2.5.3+
Fix from $2,300 2018-07-20
Ambari HIGH 8.1
CVE-2018-8042

Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credent…

Fix: after 2.6.2
Fix from $1,950 2018-07-18
HTTP Server HIGH 7.5
CVE-2018-8011EPSS 56%

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This coul…

Mitigation only
Fix from $1,950 2018-07-18
Spark MEDIUM 5.4
CVE-2018-8024EPSS 5%

In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's j…

Fix: after 2.2.1
Fix from $1,600 2018-07-12
Couchdb HIGH 7.2
CVE-2018-8007EPSS 12%

Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configura…

Fix: after 2.1.1
Fix from $1,950 2018-07-11
Storm HIGH 8.8
CVE-2018-1331

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm c…

Fix: after 1.2.1
Fix from $1,950 2018-07-10
Directory Ldap Api CRITICAL 9.8
CVE-2018-1337EPSS 5%

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before…

Fix: 1.0.2+
Fix from $2,300 2018-07-10
Solr MEDIUM 5.5
CVE-2018-8026EPSS 9%

This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.…

Fix: after 7.3.1
Fix from $1,600 2018-07-05
Cxf Fediz HIGH 7.5
CVE-2018-8038EPSS 11%

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response…

Fix: 1.4.4+
Fix from $1,950 2018-07-05
Pdfbox MEDIUM 6.5
CVE-2018-8036

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of m…

Fix: after 2.0.10
Fix from $1,600 2018-07-03
Cxf HIGH 8.1
CVE-2018-8039EPSS 10%

It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.s…

Fix: 3.1.16 / 3.2.5+
Fix from $1,950 2018-07-02
Cassandra CRITICAL 9.8
CVE-2018-8016

The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows r…

Fix: after 3.11.1
Fix from $2,300 2018-06-28
Pluto HIGH 7.5
CVE-2018-1306EPSS 44%

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive i…

No fix yet
Fix from $1,950 2018-06-27
Hbase HIGH 8.1
CVE-2018-8025

CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-condition wh…

Fix: after 2.0.0
Fix from $1,950 2018-06-27
Qpid Broker J HIGH 7.5
CVE-2018-8030

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish mes…

Fix: after 7.0.4
Fix from $1,950 2018-06-20
HTTP Server HIGH 7.5
CVE-2018-1333EPSS 17%

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of serv…

Fix: after 2.4.30
Fix from $1,950 2018-06-18
Geode HIGH 8.8
CVE-2017-15695

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy cod…

Fix: after 1.4.0
Fix from $1,950 2018-06-13
Mxnet MEDIUM 6.5
CVE-2018-1281

The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_…

Fix: 1.0.0+
Fix from $1,600 2018-06-08
Storm MEDIUM 6.5
CVE-2018-1332

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonat…

Fix: after 1.2.1
Fix from $1,600 2018-06-05
Storm MEDIUM 5.5
CVE-2018-8008

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be ac…

Fix: after 1.2.1
Fix from $1,600 2018-06-05
Batik CRITICAL 9.8
CVE-2018-8013EPSS 19%

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…

Fix: 1.10 / 7.2+
Fix from $2,300 2018-05-24
Nifi CRITICAL 9.8
CVE-2018-1309

Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The f…

Fix: 1.6.0+
Fix from $2,300 2018-05-23
Nifi HIGH 7.5
CVE-2018-1310

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE…

Fix: 1.6.0+
Fix from $1,950 2018-05-23
Zookeeper HIGH 7.5
CVE-2018-8012EPSS 8%

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-…

Fix: 3.4.10 / 19.1.0.0.1+
Fix from $1,950 2018-05-21
Solr MEDIUM 5.5
CVE-2018-8010

This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.x…

Fix: after 7.3.0
Fix from $1,600 2018-05-21