Vulnerabilities > Apache > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-08-09 | CVE-2022-36124 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Avro It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. | 7.5 |
2022-08-09 | CVE-2022-36125 | Integer Overflow or Wraparound vulnerability in Apache Avro It is possible to crash (panic) an application by providing a corrupted data to be read. | 7.5 |
2022-08-04 | CVE-2022-34158 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. | 8.8 |
2022-07-28 | CVE-2022-36364 | Improper Initialization vulnerability in Apache Calcite Avatica Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead to code execution loaded via arbitrary classes and in rare cases remote code execution. | 8.8 |
2022-07-24 | CVE-2022-24294 | Unspecified vulnerability in Apache Mxnet A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. | 7.5 |
2022-07-19 | CVE-2022-34169 | Incorrect Conversion between Numeric Types vulnerability in multiple products The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. | 7.5 |
2022-07-18 | CVE-2022-36127 | Unspecified vulnerability in Apache Skywalking A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. | 7.5 |
2022-07-18 | CVE-2022-33891 | OS Command Injection vulnerability in Apache Spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. | 8.8 |
2022-07-16 | CVE-2021-34538 | Missing Authentication for Critical Function vulnerability in Apache Hive Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. | 7.5 |
2022-07-13 | CVE-2022-31781 | Unspecified vulnerability in Apache Tapestry Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. | 7.5 |