Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2021-03-05 CVE-2021-27907 Cross-site Scripting vulnerability in Apache Superset
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information.
network
low complexity
apache CWE-79
5.4
2021-03-02 CVE-2020-1936 Cross-site Scripting vulnerability in Apache Ambari
A cross-site scripting issue was found in Apache Ambari Views.
network
apache CWE-79
4.3
2021-03-01 CVE-2020-9479 Path Traversal vulnerability in Apache Asterixdb
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory.
local
low complexity
apache CWE-22
5.5
2021-03-01 CVE-2021-25329 The fix for CVE-2020-9484 was incomplete.
local
high complexity
apache debian oracle
7.0
2021-03-01 CVE-2021-25122 Information Exposure vulnerability in multiple products
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
network
low complexity
apache debian oracle CWE-200
7.5
2021-02-26 CVE-2020-27223 Resource Exhaustion vulnerability in multiple products
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e.
network
low complexity
eclipse apache netapp debian oracle CWE-400
5.3
2021-02-24 CVE-2020-11988 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser.
network
low complexity
apache fedoraproject CWE-918
8.2
2021-02-24 CVE-2020-11987 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel.
network
low complexity
apache fedoraproject oracle debian CWE-918
8.2
2021-02-20 CVE-2021-26544 Cross-site Scripting vulnerability in Apache Livy 0.7.0Incubating
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name.
network
apache CWE-79
3.5
2021-02-19 CVE-2021-26296 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens.
network
high complexity
apache netapp CWE-352
5.1