Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2024-03-29 CVE-2024-23539 Unspecified vulnerability in Apache Fineract
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
network
low complexity
apache
critical
9.8
2024-03-14 CVE-2024-28746 Unspecified vulnerability in Apache Airflow 2.8.0/2.8.1/2.8.2
Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
network
low complexity
apache
8.1
2024-03-12 CVE-2022-34321 Unspecified vulnerability in Apache Pulsar
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication.
network
low complexity
apache
8.2
2024-03-12 CVE-2024-27135 Unspecified vulnerability in Apache Pulsar
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions.
network
low complexity
apache
critical
9.9
2024-03-12 CVE-2024-27317 Unspecified vulnerability in Apache Pulsar
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files.
network
low complexity
apache
critical
9.9
2024-03-12 CVE-2024-27894 Unspecified vulnerability in Apache Pulsar
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL.
network
low complexity
apache
8.8
2024-03-12 CVE-2024-28098 Unspecified vulnerability in Apache Pulsar
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings.
network
low complexity
apache
5.4
2024-02-29 CVE-2024-23807 Unspecified vulnerability in Apache Xerces-C++
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing.
network
low complexity
apache
critical
9.8
2024-02-29 CVE-2024-23946 Unspecified vulnerability in Apache Ofbiz
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
network
low complexity
apache
5.3
2024-02-28 CVE-2024-24772 SQL Injection vulnerability in Apache Superset
A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
network
low complexity
apache CWE-89
4.3