Vulnerabilities > Apache
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-19 | CVE-2022-47500 | Open Redirect vulnerability in Apache Helix 0.9.10/0.9.9 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding. User please upgrade to 1.1.0 to fix this issue. | 6.1 |
2022-12-16 | CVE-2021-28655 | Improper Input Validation vulnerability in Apache Zeppelin The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files. | 6.5 |
2022-12-16 | CVE-2022-46870 | Cross-site Scripting vulnerability in Apache Zeppelin An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. | 5.4 |
2022-12-15 | CVE-2022-32531 | Improper Certificate Validation vulnerability in Apache Bookkeeper The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. | 5.9 |
2022-12-14 | CVE-2022-34271 | Path Traversal vulnerability in Apache Atlas A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. | 8.8 |
2022-12-13 | CVE-2022-46364 | Server-Side Request Forgery (SSRF) vulnerability in Apache CXF A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. | 9.8 |
2022-12-13 | CVE-2022-46363 | Improper Input Validation vulnerability in Apache CXF A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. | 7.5 |
2022-12-07 | CVE-2022-45910 | Injection vulnerability in Apache Manifoldcf Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions. | 5.3 |
2022-12-03 | CVE-2021-37533 | Improper Input Validation vulnerability in multiple products Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. | 6.5 |
2022-12-02 | CVE-2022-46366 | Deserialization of Untrusted Data vulnerability in Apache Tapestry Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. | 9.8 |