Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-04 CVE-2021-31164 Injection vulnerability in Apache Unomi
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
network
low complexity
apache CWE-74
7.5
2021-04-27 CVE-2021-30638 Incorrect Authorization vulnerability in Apache Tapestry
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL.
network
low complexity
apache CWE-863
7.5
2021-04-27 CVE-2020-17517 Missing Authentication for Critical Function vulnerability in Apache Ozone 0.4.2/0.5.0/1.0.0
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default.
network
low complexity
apache CWE-306
7.5
2021-04-21 CVE-2020-23922 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in giflib through 5.1.4.
local
low complexity
giflib-project apache CWE-125
7.1
2021-04-15 CVE-2021-30245 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Apache Openoffice
The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks.
network
low complexity
apache CWE-610
8.8
2021-04-13 CVE-2021-29262 Insufficiently Protected Credentials vulnerability in Apache Solr
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable.
network
low complexity
apache CWE-522
7.5
2021-04-02 CVE-2021-22696 Server-Side Request Forgery (SSRF) vulnerability in multiple products
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)).
network
low complexity
apache oracle CWE-918
7.5
2021-03-30 CVE-2021-26919 Unspecified vulnerability in Apache Druid
Apache Druid allows users to read data from other database systems using JDBC.
network
low complexity
apache
8.8
2021-03-17 CVE-2020-17525 NULL Pointer Dereference vulnerability in multiple products
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL.
network
low complexity
apache debian CWE-476
7.5
2021-03-17 CVE-2020-13924 Path Traversal vulnerability in Apache Ambari
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
network
low complexity
apache CWE-22
7.5