Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-04-26 CVE-2022-24706 Unspecified vulnerability in Apache Couchdb
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges.
network
low complexity
apache
critical
9.8
2022-04-20 CVE-2022-29266 Information Exposure Through an Error Message vulnerability in Apache Apisix
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.
network
low complexity
apache CWE-209
7.5
2022-04-13 CVE-2022-27479 SQL Injection vulnerability in Apache Superset
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests.
network
low complexity
apache CWE-89
critical
9.8
2022-04-12 CVE-2021-28544 Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules.
network
low complexity
apache debian fedoraproject apple
4.3
2022-04-12 CVE-2022-24070 Use After Free vulnerability in multiple products
Subversion's mod_dav_svn is vulnerable to memory corruption.
network
low complexity
apache debian fedoraproject apple CWE-416
7.5
2022-04-12 CVE-2021-31805 Expression Language Injection vulnerability in Apache Struts
The fix issued for CVE-2020-17530 was incomplete.
network
low complexity
apache CWE-917
critical
9.8
2022-04-07 CVE-2022-26612 Link Following vulnerability in Apache Hadoop
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes.
network
low complexity
apache CWE-59
critical
9.8
2022-04-06 CVE-2022-26850 Exposure of Resource to Wrong Sphere vulnerability in Apache Nifi 1.14.0/1.15.0/1.15.3
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory.
network
low complexity
apache CWE-668
4.3
2022-04-05 CVE-2022-23974 Uncontrolled Recursion vulnerability in Apache Pinot
In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables.
network
low complexity
apache CWE-674
7.5
2022-03-30 CVE-2022-25598 Unspecified vulnerability in Apache Dolphinscheduler
Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.
network
low complexity
apache
7.5