Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2020-04-28 CVE-2020-9482 Insufficient Session Expiration vulnerability in Apache Nifi Registry 0.1.0/0.5.0
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side.
network
low complexity
apache CWE-613
6.5
2020-04-27 CVE-2020-9481 Resource Exhaustion vulnerability in multiple products
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
network
low complexity
apache debian CWE-400
7.5
2020-04-27 CVE-2020-1952 Improper Certificate Validation vulnerability in Apache Iotdb
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2.
network
low complexity
apache CWE-295
critical
9.8
2020-04-27 CVE-2020-9488 Improper Certificate Validation vulnerability in multiple products
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.
network
high complexity
apache oracle debian qos CWE-295
3.7
2020-04-27 CVE-2020-9489 Infinite Loop vulnerability in multiple products
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser.
local
low complexity
apache oracle CWE-835
5.5
2020-04-16 CVE-2020-1964 Deserialization of Untrusted Data vulnerability in Apache Heron 0.20.0Incubating/0.20.1Incubating/0.20.2Incubating
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).
network
low complexity
apache CWE-502
critical
9.8
2020-04-02 CVE-2020-1927 Open Redirect vulnerability in multiple products
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
6.1
2020-04-01 CVE-2020-1958 Injection vulnerability in Apache Druid 0.17.0
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid.
network
low complexity
apache CWE-74
6.5
2020-04-01 CVE-2019-17564 Deserialization of Untrusted Data vulnerability in Apache Dubbo
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled.
network
low complexity
apache CWE-502
critical
9.8
2020-04-01 CVE-2018-11802 Incorrect Authorization vulnerability in Apache Solr
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection.
network
low complexity
apache CWE-863
4.3