Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-08-09 CVE-2022-36124 Allocation of Resources Without Limits or Throttling vulnerability in Apache Avro
It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.
network
low complexity
apache CWE-770
7.5
2022-08-09 CVE-2022-36125 Integer Overflow or Wraparound vulnerability in Apache Avro
It is possible to crash (panic) an application by providing a corrupted data to be read.
network
low complexity
apache CWE-190
7.5
2022-08-04 CVE-2022-25168 Unspecified vulnerability in Apache Hadoop
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell.
network
low complexity
apache
critical
9.8
2022-08-04 CVE-2022-27166 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-28730 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-28731 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
network
low complexity
apache CWE-352
6.5
2022-08-04 CVE-2022-28732 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-34158 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account.
network
low complexity
apache CWE-352
8.8
2022-07-28 CVE-2022-36364 Improper Initialization vulnerability in Apache Calcite Avatica
Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead to code execution loaded via arbitrary classes and in rare cases remote code execution.
network
low complexity
apache CWE-665
8.8
2022-07-24 CVE-2022-24294 Unspecified vulnerability in Apache Mxnet
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption.
network
low complexity
apache
7.5