Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2019-01-23 CVE-2017-17836 Credentials Management vulnerability in Apache Airflow
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow.
network
low complexity
apache CWE-255
critical
9.8
2019-01-23 CVE-2017-17835 Cross-Site Request Forgery (CSRF) vulnerability in Apache Airflow
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
network
low complexity
apache CWE-352
8.8
2019-01-23 CVE-2017-15720 Improper Input Validation vulnerability in Apache Airflow
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.
network
low complexity
apache CWE-20
8.8
2019-01-09 CVE-2018-1000421 Server-Side Request Forgery (SSRF) vulnerability in Apache Mesos
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
apache CWE-918
6.5
2019-01-09 CVE-2018-1000420 Incorrect Authorization vulnerability in Apache Mesos
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.
network
low complexity
apache CWE-863
6.5
2019-01-07 CVE-2018-1320 Improper Certificate Validation vulnerability in multiple products
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class.
network
low complexity
apache debian f5 oracle CWE-295
7.5
2019-01-07 CVE-2018-11798 File and Directory Information Exposure vulnerability in Apache Thrift
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
network
low complexity
apache CWE-538
6.5
2019-01-07 CVE-2018-11788 XXE vulnerability in Apache Karaf
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder.
network
low complexity
apache CWE-611
critical
9.8
2019-01-02 CVE-2018-17188 Unspecified vulnerability in Apache Couchdb
Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database.
network
low complexity
apache
7.2
2018-12-31 CVE-2018-17191 Unspecified vulnerability in Apache Netbeans 9.0
Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE).
network
low complexity
apache
critical
9.8