Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-49070 Code Injection vulnerability in Apache Ofbiz
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10
network
low complexity
apache CWE-94
critical
9.8
2023-11-30 CVE-2023-49735 Path Traversal vulnerability in Apache Tiles 2.0
** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key.
network
low complexity
apache CWE-22
7.5
2023-11-30 CVE-2023-49733 XXE vulnerability in Apache Cocoon 2.2.0
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
network
low complexity
apache CWE-611
critical
9.8
2023-11-30 CVE-2023-49620 Missing Authorization vulnerability in Apache Dolphinscheduler
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue.
network
low complexity
apache CWE-862
6.5
2023-11-30 CVE-2022-45135 SQL Injection vulnerability in Apache Cocoon 2.2.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
network
low complexity
apache CWE-89
critical
9.8
2023-11-28 CVE-2023-42504 Allocation of Resources Without Limits or Throttling vulnerability in Apache Superset
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0
network
low complexity
apache CWE-770
6.5
2023-11-28 CVE-2023-42502 Open Redirect vulnerability in Apache Superset
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset.
network
low complexity
apache CWE-601
5.4
2023-11-28 CVE-2023-42505 Unspecified vulnerability in Apache Superset
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
network
low complexity
apache
4.3
2023-11-28 CVE-2022-41678 Deserialization of Untrusted Data vulnerability in Apache Activemq
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject.
network
low complexity
apache CWE-502
8.8
2023-11-28 CVE-2023-46589 HTTP Request Smuggling vulnerability in Apache Tomcat
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers.
network
low complexity
apache CWE-444
7.5