Vulnerabilities > Apache > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-08-05 CVE-2020-13921 SQL Injection vulnerability in Apache Skywalking
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
network
low complexity
apache CWE-89
critical
9.8
2020-07-17 CVE-2020-11982 Deserialization of Untrusted Data vulnerability in Apache Airflow
An issue was found in Apache Airflow versions 1.10.10 and below.
network
low complexity
apache CWE-502
critical
9.8
2020-07-17 CVE-2020-11981 OS Command Injection vulnerability in Apache Airflow
An issue was found in Apache Airflow versions 1.10.10 and below.
network
low complexity
apache CWE-78
critical
9.8
2020-07-14 CVE-2020-1948 Deserialization of Untrusted Data vulnerability in Apache Dubbo
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower.
network
low complexity
apache CWE-502
critical
9.8
2020-07-14 CVE-2020-13926 SQL Injection vulnerability in Apache Kylin
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible.
network
low complexity
apache CWE-89
critical
9.8
2020-07-14 CVE-2020-13925 OS Command Injection vulnerability in Apache Kylin
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely.
network
low complexity
apache CWE-78
critical
9.8
2020-06-23 CVE-2020-9480 Missing Authentication for Critical Function vulnerability in multiple products
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret.
network
low complexity
apache oracle CWE-306
critical
9.8
2020-06-22 CVE-2020-11989 Unspecified vulnerability in Apache Shiro
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
network
low complexity
apache
critical
9.8
2020-06-15 CVE-2020-11969 Missing Authentication for Critical Function vulnerability in Apache Tomee
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication.
network
low complexity
apache CWE-306
critical
9.8
2020-06-05 CVE-2020-11975 Unspecified vulnerability in Apache Unomi 1.3.0/1.4.0/1.5.0
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
network
low complexity
apache
critical
9.8