Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2021-04-21 CVE-2020-23922 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in giflib through 5.1.4.
local
low complexity
giflib-project apache CWE-125
7.1
2021-04-15 CVE-2021-30245 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Apache Openoffice
The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks.
network
low complexity
apache CWE-610
8.8
2021-04-15 CVE-2021-27850 Deserialization of Untrusted Data vulnerability in Apache Tapestry
A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry.
network
low complexity
apache CWE-502
critical
9.8
2021-04-13 CVE-2021-29943 Incorrect Authorization vulnerability in Apache Solr
When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials.
network
low complexity
apache CWE-863
critical
9.1
2021-04-13 CVE-2021-29425 Path Traversal vulnerability in multiple products
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
network
high complexity
apache debian oracle netapp CWE-22
4.8
2021-04-13 CVE-2021-29262 Insufficiently Protected Credentials vulnerability in Apache Solr
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable.
network
low complexity
apache CWE-522
7.5
2021-04-13 CVE-2021-27905 Server-Side Request Forgery (SSRF) vulnerability in Apache Solr
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core.
network
low complexity
apache CWE-918
critical
9.8
2021-04-02 CVE-2021-22696 Server-Side Request Forgery (SSRF) vulnerability in multiple products
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)).
network
low complexity
apache oracle CWE-918
7.5
2021-04-01 CVE-2021-28163 Link Following vulnerability in multiple products
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
network
low complexity
eclipse fedoraproject apache netapp oracle CWE-59
2.7
2021-03-31 CVE-2021-28657 Infinite Loop vulnerability in multiple products
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25.
local
low complexity
apache oracle CWE-835
5.5