Vulnerabilities > Apache > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-07-17 CVE-2020-11981 OS Command Injection vulnerability in Apache Airflow
An issue was found in Apache Airflow versions 1.10.10 and below.
network
low complexity
apache CWE-78
critical
9.8
2020-07-14 CVE-2020-1948 Deserialization of Untrusted Data vulnerability in Apache Dubbo
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower.
network
low complexity
apache CWE-502
critical
9.8
2020-07-14 CVE-2020-13926 SQL Injection vulnerability in Apache Kylin
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible.
network
low complexity
apache CWE-89
critical
9.8
2020-07-14 CVE-2020-13925 OS Command Injection vulnerability in Apache Kylin
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely.
network
low complexity
apache CWE-78
critical
9.8
2020-06-23 CVE-2020-9480 Missing Authentication for Critical Function vulnerability in multiple products
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret.
network
low complexity
apache oracle CWE-306
critical
9.8
2020-06-22 CVE-2020-11989 Unspecified vulnerability in Apache Shiro
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
network
low complexity
apache
critical
9.8
2020-06-15 CVE-2020-11969 Missing Authentication for Critical Function vulnerability in Apache Tomee
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication.
network
low complexity
apache CWE-306
critical
9.8
2020-06-05 CVE-2020-11975 Unspecified vulnerability in Apache Unomi 1.3.0/1.4.0/1.5.0
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
network
low complexity
apache
critical
9.8
2020-06-03 CVE-2020-1963 Missing Authorization vulnerability in Apache Ignite
Apache Ignite uses H2 database to build SQL distributed execution engine.
network
low complexity
apache CWE-862
critical
9.1
2020-05-21 CVE-2018-21234 Deserialization of Untrusted Data vulnerability in multiple products
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
network
low complexity
jodd apache CWE-502
critical
9.8