Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2023-10-28 CVE-2023-46215 Information Exposure Through Log Files vulnerability in Apache Airflow and Airflow Celery Provider
Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Note: the vulnerability is about the information exposed in the logs not about accessing the logs. This issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3. Users are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.
network
low complexity
apache CWE-532
7.5
2023-10-27 CVE-2023-46604 Deserialization of Untrusted Data vulnerability in multiple products
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution.
network
low complexity
apache debian netapp CWE-502
critical
9.8
2023-10-23 CVE-2023-46288 Unspecified vulnerability in Apache Airflow
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only.
network
low complexity
apache
4.3
2023-10-23 CVE-2023-31122 Out-of-bounds Read vulnerability in multiple products
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
network
low complexity
apache fedoraproject CWE-125
7.5
2023-10-23 CVE-2023-43622 Resource Exhaustion vulnerability in Apache Http Server 2.4.55
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server.
network
low complexity
apache CWE-400
7.5
2023-10-23 CVE-2023-45802 Resource Exhaustion vulnerability in multiple products
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately.
network
high complexity
apache fedoraproject CWE-400
5.9
2023-10-20 CVE-2023-44483 Information Exposure Through Log Files vulnerability in Apache Santuario XML Security for Java
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
network
low complexity
apache CWE-532
6.5
2023-10-19 CVE-2023-46227 Deserialization of Untrusted Data vulnerability in Apache Inlong
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814
network
low complexity
apache CWE-502
7.5
2023-10-19 CVE-2023-25753 Server-Side Request Forgery (SSRF) vulnerability in Apache Shenyu 2.5.1
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint.
network
low complexity
apache CWE-918
6.5
2023-10-17 CVE-2023-39456 Improper Input Validation vulnerability in multiple products
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.
network
low complexity
apache fedoraproject CWE-20
7.5