Vulnerabilities > Apache > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-19 CVE-2018-17195 Incorrect Authorization vulnerability in Apache Nifi
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack.
network
high complexity
apache CWE-863
7.5
2018-12-19 CVE-2018-17194 Improper Input Validation vulnerability in Apache Nifi
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded.
network
low complexity
apache CWE-20
7.5
2018-12-13 CVE-2018-8033 Information Exposure vulnerability in Apache Ofbiz
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint.
network
low complexity
apache CWE-200
7.5
2018-11-27 CVE-2018-11766 Unspecified vulnerability in Apache Hadoop 2.7.4/2.7.5/2.7.6
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete.
network
low complexity
apache
8.8
2018-11-13 CVE-2018-8009 Path Traversal vulnerability in Apache Hadoop
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.
network
low complexity
apache CWE-22
8.8
2018-11-13 CVE-2018-17187 Improper Certificate Validation vulnerability in Apache Qpid Proton-J
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods.
network
high complexity
apache CWE-295
7.4
2018-11-08 CVE-2018-11777 Unspecified vulnerability in Apache Hive
In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.
network
low complexity
apache
8.1
2018-11-06 CVE-2018-17186 XXE vulnerability in Apache Syncope
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
network
low complexity
apache CWE-611
7.2
2018-10-31 CVE-2018-11759 Path Traversal vulnerability in multiple products
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly.
network
low complexity
apache debian redhat CWE-22
7.5
2018-10-24 CVE-2018-11804 Unspecified vulnerability in Apache Spark
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation.
network
low complexity
apache
7.5