Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2022-03-04 CVE-2022-26336 A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception.
local
low complexity
apache netapp
5.5
2022-02-25 CVE-2021-45229 Cross-site Scripting vulnerability in Apache Airflow
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
network
low complexity
apache CWE-79
6.1
2022-02-25 CVE-2022-24288 OS Command Injection vulnerability in Apache Airflow
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
network
low complexity
apache CWE-78
8.8
2022-02-25 CVE-2022-24947 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover.
network
low complexity
apache CWE-352
8.8
2022-02-25 CVE-2022-24948 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-02-11 CVE-2021-44521 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Cassandra
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host.
network
low complexity
apache CWE-732
critical
9.1
2022-02-11 CVE-2022-24112 Authentication Bypass by Spoofing vulnerability in Apache Apisix
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API.
network
low complexity
apache CWE-290
critical
9.8
2022-02-11 CVE-2022-24289 Deserialization of Untrusted Data vulnerability in Apache Cayenne
Hessian serialization is a network protocol that supports object-based transmission.
network
low complexity
apache CWE-502
8.8
2022-02-07 CVE-2022-22931 Path Traversal vulnerability in Apache James 3.6.1
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations.
network
low complexity
apache CWE-22
4.3
2022-02-06 CVE-2022-23206 Server-Side Request Forgery (SSRF) vulnerability in Apache Traffic Control
In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.
network
low complexity
apache CWE-918
7.5