Vulnerabilities > Apache

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2019-12426 Unspecified vulnerability in Apache Ofbiz
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
network
low complexity
apache
5.3
2020-01-30 CVE-2020-1931 OS Command Injection vulnerability in Apache Spamassassin
A command execution issue was found in Apache SpamAssassin prior to 3.4.3.
network
high complexity
apache CWE-78
8.1
2020-01-30 CVE-2020-1930 OS Command Injection vulnerability in Apache Spamassassin
A command execution issue was found in Apache SpamAssassin prior to 3.4.3.
network
high complexity
apache CWE-78
8.1
2020-01-29 CVE-2019-20445 HTTP Request Smuggling vulnerability in multiple products
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
network
low complexity
netty debian fedoraproject canonical redhat apache CWE-444
critical
9.1
2020-01-28 CVE-2020-1940 Improper Cross-boundary Removal of Sensitive Data vulnerability in Apache Jackrabbit OAK
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability.
network
low complexity
apache CWE-212
7.5
2020-01-28 CVE-2020-1933 Cross-site Scripting vulnerability in Apache Nifi
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0.
network
low complexity
apache CWE-79
6.1
2020-01-28 CVE-2020-1932 Unspecified vulnerability in Apache Superset
An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1.
network
low complexity
apache
6.5
2020-01-28 CVE-2020-1928 Information Exposure Through Log Files vulnerability in Apache Nifi 1.10.0
An information disclosure vulnerability was found in Apache NiFi 1.10.0.
network
low complexity
apache CWE-532
5.3
2020-01-23 CVE-2019-17570 Deserialization of Untrusted Data vulnerability in multiple products
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library.
network
low complexity
apache debian canonical fedoraproject redhat CWE-502
critical
9.8
2020-01-16 CVE-2019-17573 Cross-site Scripting vulnerability in multiple products
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses.
network
low complexity
apache oracle CWE-79
6.1