Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-10-06 CVE-2022-40159 Out-of-bounds Write vulnerability in Apache Commons Jxpath
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation.
network
low complexity
apache CWE-787
6.5
2022-10-06 CVE-2022-40160 Out-of-bounds Write vulnerability in Apache Commons Jxpath
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation.
network
low complexity
apache CWE-787
6.5
2022-09-28 CVE-2021-43980 The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance resulting in responses, or part responses, to be received by the wrong client.
network
high complexity
apache debian
3.7
2022-09-23 CVE-2022-24280 Improper Input Validation vulnerability in Apache Pulsar
Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address.
network
low complexity
apache CWE-20
6.5
2022-09-23 CVE-2022-33681 Improper Certificate Validation vulnerability in Apache Pulsar
Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack.
network
high complexity
apache CWE-295
5.9
2022-09-23 CVE-2022-33682 Improper Certificate Validation vulnerability in Apache Pulsar
TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication connections vulnerable to man in the middle attacks, which could leak credentials, configuration data, message data, and any other data sent by these clients.
network
high complexity
apache CWE-295
5.9
2022-09-23 CVE-2022-33683 Improper Certificate Validation vulnerability in Apache Pulsar
Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration.
network
high complexity
apache CWE-295
5.9
2022-09-23 CVE-2022-26112 Unspecified vulnerability in Apache Pinot
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support.
network
low complexity
apache
critical
9.8
2022-09-22 CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol.
network
low complexity
apache debian
5.3
2022-09-22 CVE-2022-38648 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources.
network
low complexity
apache debian
5.3