Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2024-08-05 CVE-2024-36448 Unspecified vulnerability in Apache Iotdb Workbench 0.13.0
** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue.
network
low complexity
apache
7.3
2024-08-05 CVE-2024-38856 Unspecified vulnerability in Apache Ofbiz
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
network
low complexity
apache
critical
9.8
2024-08-05 CVE-2024-42447 Unspecified vulnerability in Apache Apache-Airflow-Providers-Fab 1.2.0/1.2.1
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions.
network
low complexity
apache
critical
9.8
2024-08-02 CVE-2024-27182 Files or Directories Accessible to External Parties vulnerability in Apache Linkis 1.3.2/1.4.0/1.5.0
In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue.
network
low complexity
apache CWE-552
4.9
2024-08-02 CVE-2024-36268 Unspecified vulnerability in Apache Inlong 1.10.0/1.11.0/1.12.0
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution.
network
low complexity
apache
critical
9.8
2024-07-26 CVE-2023-38522 Unspecified vulnerability in Apache Traffic Server
Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers.
network
low complexity
apache
7.5
2024-07-26 CVE-2024-35161 Unspecified vulnerability in Apache Traffic Server
Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers.
network
low complexity
apache
7.5
2024-07-26 CVE-2024-35296 Unspecified vulnerability in Apache Traffic Server
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.
network
low complexity
apache
8.2
2024-07-26 CVE-2024-25090 Unspecified vulnerability in Apache Roller
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack.
network
low complexity
apache
5.4
2024-07-24 CVE-2023-48362 Unspecified vulnerability in Apache Drill
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.
network
low complexity
apache
8.8