Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-10-25 CVE-2022-41704 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG.
network
low complexity
apache debian CWE-918
7.5
2022-10-25 CVE-2022-42890 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript.
network
low complexity
apache debian CWE-918
7.5
2022-10-24 CVE-2021-42010 Improper Encoding or Escaping of Output vulnerability in Apache Heron
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements.
network
low complexity
apache CWE-116
critical
9.8
2022-10-19 CVE-2022-42466 Unspecified vulnerability in Apache Isis
Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved.
network
low complexity
apache
6.1
2022-10-19 CVE-2022-42467 Insecure Default Initialization of Resource vulnerability in Apache Isis
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database.
network
low complexity
apache CWE-1188
5.3
2022-10-18 CVE-2022-39198 Unspecified vulnerability in Apache Dubbo
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution.
network
low complexity
apache
critical
9.8
2022-10-13 CVE-2022-24697 OS Command Injection vulnerability in Apache Kylin
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu.
network
low complexity
apache CWE-78
critical
9.8
2022-10-13 CVE-2022-42889 Code Injection vulnerability in multiple products
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.
network
low complexity
apache netapp juniper CWE-94
critical
9.8
2022-10-12 CVE-2022-40664 Unspecified vulnerability in Apache Shiro
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
network
low complexity
apache
critical
9.8
2022-10-07 CVE-2022-41672 Unspecified vulnerability in Apache Airflow
In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.
network
low complexity
apache
8.1