Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2024-07-19 CVE-2024-41172 Unspecified vulnerability in Apache CXF
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
network
low complexity
apache
7.5
2024-07-18 CVE-2024-29178 Unspecified vulnerability in Apache Streampark
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigation: all users should upgrade to 2.1.4
network
low complexity
apache
8.8
2024-07-18 CVE-2024-40725 Unspecified vulnerability in Apache Http Server 2.4.60/2.4.61
A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers.
network
low complexity
apache
5.3
2024-07-18 CVE-2024-40898 Unspecified vulnerability in Apache Http Server
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 
network
low complexity
apache
7.5
2024-07-17 CVE-2024-31411 Unspecified vulnerability in Apache Streampipes
Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue affects Apache StreamPipes: through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.
network
low complexity
apache
8.8
2024-07-17 CVE-2023-52291 Unspecified vulnerability in Apache Streampark
In streampark, the project module integrates Maven's compilation capabilities.
network
low complexity
apache
4.7
2024-07-17 CVE-2024-29737 Unspecified vulnerability in Apache Streampark
In streampark, the project module integrates Maven's compilation capabilities.
network
low complexity
apache
4.7
2024-07-17 CVE-2024-30471 Unspecified vulnerability in Apache Streampipes
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is registered, creating many identical users and corrupting StreamPipe's user management. This issue affects Apache StreamPipes: through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.
network
high complexity
apache
3.7
2024-07-17 CVE-2024-31979 Unspecified vulnerability in Apache Streampipes
Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements.
network
low complexity
apache
4.3
2024-07-17 CVE-2024-39863 Cross-site Scripting vulnerability in Apache Airflow
Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider.
network
low complexity
apache CWE-79
5.4