Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2023-02-04 CVE-2022-45786 Unspecified vulnerability in Apache AGE
There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur.
network
high complexity
apache
8.1
2023-02-04 CVE-2023-22849 Unspecified vulnerability in Apache Sling CMS
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features. Upgrade to Apache Sling App CMS >= 1.1.6
network
low complexity
apache
6.1
2023-02-01 CVE-2023-24997 Unspecified vulnerability in Apache Inlong
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223 https://github.com/apache/inlong/pull/7223  to solve it.
network
low complexity
apache
critical
9.8
2023-02-01 CVE-2023-24977 Unspecified vulnerability in Apache Inlong
Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 https://github.com/apache/inlong/pull/7214  to solve it.
network
low complexity
apache
7.5
2023-01-31 CVE-2022-24963 Unspecified vulnerability in Apache Portable Runtime 1.7.0
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.
network
low complexity
apache
critical
9.8
2023-01-31 CVE-2022-25147 Unspecified vulnerability in Apache Portable Runtime Utility
Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.
network
low complexity
apache
6.5
2023-01-31 CVE-2022-28331 Unspecified vulnerability in Apache Portable Runtime
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv().
network
low complexity
apache
critical
9.8
2023-01-31 CVE-2022-44644 Unspecified vulnerability in Apache Linkis
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter.
network
low complexity
apache
6.5
2023-01-31 CVE-2022-44645 Unspecified vulnerability in Apache Linkis
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters.
network
low complexity
apache
8.8
2023-01-31 CVE-2023-24829 Unspecified vulnerability in Apache Iotdb 0.13.0/0.13.1/0.13.2
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3.
network
low complexity
apache
8.8