Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2017-05-26 CVE-2017-5646 Origin Validation Error vulnerability in Apache Knox
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox.
network
high complexity
apache CWE-346
6.8
2017-05-22 CVE-2017-6891 Out-of-bounds Write vulnerability in multiple products
Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g.
network
low complexity
gnu debian apache CWE-787
8.8
2017-05-22 CVE-2017-5657 Cross-Site Request Forgery (CSRF) vulnerability in Apache Archiva
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks.
network
low complexity
apache CWE-352
8.0
2017-05-19 CVE-2015-5241 Open Redirect vulnerability in Apache Juddi
After logging into the portal, the logout jsp page redirects the browser back to the login page after.
network
low complexity
apache CWE-601
6.1
2017-05-16 CVE-2017-7662 Cross-Site Request Forgery (CSRF) vulnerability in Apache CXF Fediz
Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc.
network
low complexity
apache CWE-352
8.8
2017-05-16 CVE-2017-7661 Cross-Site Request Forgery (CSRF) vulnerability in Apache CXF Fediz
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications.
network
low complexity
apache CWE-352
8.8
2017-05-15 CVE-2017-5655 Information Exposure vulnerability in Apache Ambari
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host.
network
low complexity
apache CWE-200
6.5
2017-05-15 CVE-2016-8741 Information Exposure vulnerability in Apache Qpid Broker-J
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication.
network
low complexity
apache CWE-200
7.5
2017-05-12 CVE-2017-5654 XML Injection (aka Blind XPath Injection) vulnerability in Apache Ambari 2.4.0/2.4.1/2.5.0
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.
network
low complexity
apache CWE-91
7.5
2017-05-09 CVE-2016-6799 Information Exposure Through Log Files vulnerability in Apache Cordova
Product: Apache Cordova Android 5.2.2 and earlier.
network
low complexity
apache CWE-532
7.5