Vulnerabilities > Apache > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-11-07 CVE-2022-37865 Path Traversal vulnerability in Apache IVY 2.4.0/2.5.0
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging.
network
low complexity
apache CWE-22
critical
9.1
2022-10-26 CVE-2022-42468 Injection vulnerability in Apache Flume
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL.
network
low complexity
apache CWE-74
critical
9.8
2022-10-24 CVE-2021-42010 Improper Encoding or Escaping of Output vulnerability in Apache Heron
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements.
network
low complexity
apache CWE-116
critical
9.8
2022-10-18 CVE-2022-39198 Deserialization of Untrusted Data vulnerability in Apache Dubbo
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution.
network
low complexity
apache CWE-502
critical
9.8
2022-10-13 CVE-2022-24697 OS Command Injection vulnerability in Apache Kylin
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu.
network
low complexity
apache CWE-78
critical
9.8
2022-10-13 CVE-2022-42889 Code Injection vulnerability in multiple products
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.
network
low complexity
apache netapp juniper CWE-94
critical
9.8
2022-10-12 CVE-2022-40664 Improper Authentication vulnerability in Apache Shiro
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
network
low complexity
apache CWE-287
critical
9.8
2022-09-23 CVE-2022-26112 Unspecified vulnerability in Apache Pinot
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support.
network
low complexity
apache
critical
9.8
2022-09-11 CVE-2022-39135 XXE vulnerability in Apache Calcite
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack.
network
low complexity
apache CWE-611
critical
9.8
2022-09-02 CVE-2022-25371 Path Traversal vulnerability in Apache Ofbiz
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports.
network
low complexity
apache CWE-22
critical
9.8