Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2024-07-24 CVE-2024-39676 Information Exposure vulnerability in Apache Pinot
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue. Details:  When using a request to path “/appconfigs” to the controller, it can lead to the disclosure of sensitive information such as system information (e.g.
network
low complexity
apache CWE-200
7.5
2024-07-22 CVE-2024-23321 Unspecified vulnerability in Apache Rocketmq
For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially acquire the administrator's account and password through specific interfaces.
network
low complexity
apache
8.8
2024-07-22 CVE-2024-34457 Unspecified vulnerability in Apache Streampark
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4
network
low complexity
apache
6.5
2024-07-22 CVE-2024-38503 Unspecified vulnerability in Apache Syncope
When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
network
low complexity
apache
5.4
2024-07-19 CVE-2024-41107 Unspecified vulnerability in Apache Cloudstack
The CloudStack SAML authentication (disabled by default) does not enforce signature check.
network
high complexity
apache
8.1
2024-07-19 CVE-2024-29736 Unspecified vulnerability in Apache CXF
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices.
network
low complexity
apache
critical
9.1
2024-07-19 CVE-2024-32007 Unspecified vulnerability in Apache CXF
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 
network
low complexity
apache
7.5
2024-07-19 CVE-2024-41172 Unspecified vulnerability in Apache CXF
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
network
low complexity
apache
7.5
2024-07-18 CVE-2024-29178 Unspecified vulnerability in Apache Streampark
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigation: all users should upgrade to 2.1.4
network
low complexity
apache
8.8
2024-07-18 CVE-2024-40725 Unspecified vulnerability in Apache Http Server 2.4.60/2.4.61
A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers.
network
low complexity
apache
5.3