Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-27 CVE-2023-49145 Cross-site Scripting vulnerability in Apache Nifi
Apache NiFi 0.7.0 through 1.23.2 include the JoltTransformJSON Processor, which provides an advanced configuration user interface that is vulnerable to DOM-based cross-site scripting.
network
low complexity
apache CWE-79
5.4
2023-11-27 CVE-2023-42501 Incorrect Default Permissions vulnerability in Apache Superset
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission from the mentioned resources.
network
low complexity
apache CWE-276
4.3
2023-11-27 CVE-2023-43701 Cross-site Scripting vulnerability in Apache Superset
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue affects Apache Superset versions prior to 2.1.2.  Users are recommended to upgrade to version 2.1.2, which fixes this issue.
network
low complexity
apache CWE-79
5.4
2023-11-23 CVE-2023-43123 Unspecified vulnerability in Apache Storm
On unix-like systems, the temporary directory is shared between all user.
local
low complexity
apache
5.5
2023-11-12 CVE-2023-42781 Unspecified vulnerability in Apache Airflow
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of Apache Airflow are advised to upgrade to version 2.7.3 or newer to mitigate the risk associated with this vulnerability.
network
low complexity
apache
6.5
2023-11-12 CVE-2023-47037 Incorrect Authorization vulnerability in Apache Airflow
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.
network
low complexity
apache CWE-863
4.3
2023-11-07 CVE-2023-46819 Missing Authentication for Critical Function vulnerability in Apache Ofbiz
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Users are recommended to upgrade to version 18.12.09
network
low complexity
apache CWE-306
5.3
2023-11-07 CVE-2023-46851 External Control of File Name or Path vulnerability in Apache Allura
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments.
network
low complexity
apache CWE-73
4.9
2023-10-23 CVE-2023-46288 Unspecified vulnerability in Apache Airflow
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only.
network
low complexity
apache
4.3
2023-10-23 CVE-2023-45802 Resource Exhaustion vulnerability in multiple products
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately.
network
high complexity
apache fedoraproject CWE-400
5.9