Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2020-05-14 CVE-2019-17572 Path Traversal vulnerability in Apache Rocketmq
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability.
network
low complexity
apache CWE-22
5.3
2020-05-14 CVE-2019-17562 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apache Cloudstack
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack.
network
low complexity
apache CWE-119
critical
9.8
2020-05-14 CVE-2020-1945 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information.
6.3
2020-05-12 CVE-2020-1939 NULL Pointer Dereference vulnerability in Apache Nuttx
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs.
network
low complexity
apache CWE-476
critical
9.8
2020-05-11 CVE-2018-1285 XXE vulnerability in multiple products
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files.
network
low complexity
apache fedoraproject oracle netapp CWE-611
critical
9.8
2020-05-04 CVE-2020-1961 Injection vulnerability in Apache Syncope
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.
network
low complexity
apache CWE-74
critical
9.8
2020-05-04 CVE-2020-1959 Expression Language Injection vulnerability in Apache Syncope
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability.
network
low complexity
apache CWE-917
critical
9.8
2020-05-04 CVE-2019-17557 Cross-site Scripting vulnerability in Apache Syncope
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters.
network
low complexity
apache CWE-79
5.4
2020-04-30 CVE-2019-12425 Injection vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
network
low complexity
apache CWE-74
7.5
2020-04-30 CVE-2019-0235 Cross-Site Request Forgery (CSRF) vulnerability in Apache Ofbiz 17.12.01
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
network
low complexity
apache CWE-352
8.8