Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2018-08-29 CVE-2018-1318 Improper Input Validation vulnerability in multiple products
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request.
network
low complexity
apache debian CWE-20
7.5
2018-08-26 CVE-2011-2767 Code Injection vulnerability in multiple products
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
network
low complexity
apache debian redhat canonical CWE-94
critical
9.8
2018-08-23 CVE-2018-8028 Missing Authorization vulnerability in Apache Sentry
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1.
network
low complexity
apache CWE-862
8.8
2018-08-22 CVE-2018-11758 XXE vulnerability in Apache Cayenne
This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2.
network
low complexity
apache CWE-611
8.1
2018-08-22 CVE-2018-11776 Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
network
high complexity
apache netapp oracle
8.1
2018-08-16 CVE-2018-11771 Infinite Loop vulnerability in multiple products
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached.
local
low complexity
apache oracle CWE-835
5.5
2018-08-14 CVE-2016-4975 CRLF Injection vulnerability in Apache Http Server
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir.
network
low complexity
apache CWE-93
6.1
2018-08-13 CVE-2018-11770 Improper Authentication vulnerability in Apache Spark
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit.
network
high complexity
apache CWE-287
4.2
2018-08-08 CVE-2018-11769 Unspecified vulnerability in Apache Couchdb
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S).
network
low complexity
apache
7.2
2018-08-06 CVE-2017-12614 Cross-site Scripting vulnerability in Apache Airflow
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack.
network
low complexity
apache CWE-79
6.1