Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2024-06-20 CVE-2024-34693 Unspecified vulnerability in Apache Superset
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled.
network
high complexity
apache
5.3
2024-06-14 CVE-2024-25142 Unspecified vulnerability in Apache Airflow
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.
local
low complexity
apache
5.5
2024-06-12 CVE-2024-36265 Unspecified vulnerability in Apache Submarine 0.8.0
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue.
network
low complexity
apache
critical
9.8
2024-06-12 CVE-2024-36264 Unspecified vulnerability in Apache Submarine 0.8.0
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this project is retired, we do not plan to release a version that fixes this issue.
network
low complexity
apache
critical
9.8
2024-05-14 CVE-2024-32077 Unspecified vulnerability in Apache Airflow 2.9.0
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.
network
low complexity
apache
5.4
2024-05-08 CVE-2024-26579 Unspecified vulnerability in Apache Inlong
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. [1] https://github.com/apache/inlong/pull/9694 [2]  https://github.com/apache/inlong/pull/9707
network
low complexity
apache
critical
9.8
2024-05-08 CVE-2024-32113 Unspecified vulnerability in Apache Ofbiz
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
network
low complexity
apache
critical
9.8
2024-05-07 CVE-2024-28148 Unspecified vulnerability in Apache Superset
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
network
low complexity
apache
4.3
2024-05-02 CVE-2024-32114 Unspecified vulnerability in Apache Activemq
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication.
network
low complexity
apache
8.8
2024-04-22 CVE-2024-27348 Unspecified vulnerability in Apache Hugegraph 1.0.0/1.2.0
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
network
low complexity
apache
critical
9.8