Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-37924 SQL Injection vulnerability in Apache Submarine 0.7.0
Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in.
network
low complexity
apache CWE-89
critical
9.8
2023-11-20 CVE-2022-46337 Injection vulnerability in Apache Derby
A cleverly devised username might bypass LDAP authentication checks.
network
low complexity
apache CWE-74
critical
9.8
2023-11-20 CVE-2023-46302 Deserialization of Untrusted Data vulnerability in Apache Submarine 0.7.0
Apache Software Foundation Apache Submarine has a bug when serializing against yaml.
network
low complexity
apache CWE-502
critical
9.8
2023-11-16 CVE-2023-26031 Untrusted Search Path vulnerability in Apache Hadoop 3.3.1/3.3.2/3.3.4
Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges.
network
high complexity
apache CWE-426
7.5
2023-11-12 CVE-2023-42781 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.
network
low complexity
apache
6.5
2023-11-12 CVE-2023-47037 Incorrect Authorization vulnerability in Apache Airflow
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.
network
low complexity
apache CWE-863
4.3
2023-11-09 CVE-2023-47248 Deserialization of Untrusted Data vulnerability in Apache Pyarrow
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution.
network
low complexity
apache CWE-502
critical
9.8
2023-11-08 CVE-2023-39913 Deserialization of Untrusted Data vulnerability in Apache Uimaj
Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. There are several locations in the code where serialized Java objects are deserialized without verifying the data.
network
low complexity
apache CWE-502
8.8
2023-11-07 CVE-2023-46819 Missing Authentication for Critical Function vulnerability in Apache Ofbiz
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Users are recommended to upgrade to version 18.12.09
network
low complexity
apache CWE-306
5.3
2023-11-07 CVE-2023-46851 External Control of File Name or Path vulnerability in Apache Allura
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments.
network
low complexity
apache CWE-73
4.9