Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2021-01-14 CVE-2021-24122 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations.
network
high complexity
apache debian oracle CWE-706
5.9
2021-01-14 CVE-2021-23926 XML Entity Expansion vulnerability in multiple products
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input.
network
low complexity
apache netapp debian oracle CWE-776
critical
9.1
2021-01-11 CVE-2020-17534 Race Condition vulnerability in Apache Html/Java API 1.7
There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7.
local
high complexity
apache CWE-362
7.0
2021-01-11 CVE-2020-17509 HTTP Request Smuggling vulnerability in Apache Traffic Server
ATS negative cache option is vulnerable to a cache poisoning attack.
network
low complexity
apache CWE-444
7.5
2021-01-11 CVE-2020-17508 Unspecified vulnerability in Apache Traffic Server
The ATS ESI plugin has a memory disclosure vulnerability.
network
low complexity
apache
7.5
2021-01-11 CVE-2020-13922 Incorrect Default Permissions vulnerability in Apache Dolphinscheduler 1.2.0/1.2.1/1.3.1
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
network
low complexity
apache CWE-276
6.5
2021-01-11 CVE-2020-11995 Deserialization of Untrusted Data vulnerability in Apache Dubbo
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution.
network
low complexity
apache CWE-502
critical
9.8
2021-01-05 CVE-2020-17519 Files or Directories Accessible to External Parties vulnerability in Apache Flink 1.11.0/1.11.1/1.11.2
A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process.
network
low complexity
apache CWE-552
7.5
2021-01-05 CVE-2020-17518 Path Traversal vulnerability in Apache Flink
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER.
network
low complexity
apache CWE-22
7.5
2020-12-29 CVE-2020-17533 Unspecified vulnerability in Apache Accumulo
Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting an authenticated user to perform certain administrative operations.
network
low complexity
apache
8.1