Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-11-02 CVE-2022-43982 Cross-site Scripting vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
network
low complexity
apache CWE-79
6.1
2022-11-02 CVE-2022-43985 Unspecified vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
network
low complexity
apache
6.1
2022-11-01 CVE-2022-31777 Unspecified vulnerability in Apache Spark
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.
network
low complexity
apache
5.4
2022-11-01 CVE-2022-34662 Unspecified vulnerability in Apache Dolphinscheduler
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users.
network
low complexity
apache
6.5
2022-11-01 CVE-2022-42252 Unspecified vulnerability in Apache Tomcat
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
network
low complexity
apache
7.5
2022-10-28 CVE-2022-26884 Path Traversal vulnerability in Apache Dolphinscheduler
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
network
low complexity
apache CWE-22
6.5
2022-10-26 CVE-2022-39944 Deserialization of Untrusted Data vulnerability in Apache Linkis
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious parameters.
network
low complexity
apache CWE-502
8.8
2022-10-26 CVE-2022-42468 Unspecified vulnerability in Apache Flume 1.10.0/1.4.0/1.9.0
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL.
network
low complexity
apache
critical
9.8
2022-10-26 CVE-2022-43766 Unspecified vulnerability in Apache Iotdb
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8.
network
low complexity
apache
7.5
2022-10-25 CVE-2022-34870 Cross-site Scripting vulnerability in Apache Geode
Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.
network
low complexity
apache CWE-79
5.4