Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-16 CVE-2021-28655 Unspecified vulnerability in Apache Zeppelin
The improper Input Validation vulnerability in "”Move folder to Trash” feature of Apache Zeppelin allows an attacker to delete the arbitrary files.
network
low complexity
apache
6.5
2022-12-16 CVE-2022-46870 Unspecified vulnerability in Apache Zeppelin
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2.
network
low complexity
apache
5.4
2022-12-15 CVE-2022-32531 Unspecified vulnerability in Apache Bookkeeper
The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails.
network
high complexity
apache
5.9
2022-12-07 CVE-2022-45910 Injection vulnerability in Apache Manifoldcf
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions.
network
low complexity
apache CWE-74
5.3
2022-12-03 CVE-2021-37533 Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default.
network
low complexity
apache debian
6.5
2022-11-22 CVE-2022-40954 OS Command Injection vulnerability in Apache Airflow
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files.
local
low complexity
apache CWE-78
5.5
2022-11-15 CVE-2022-40309 Unspecified vulnerability in Apache Archiva
Users with write permissions to a repository can delete arbitrary directories.
network
low complexity
apache
4.3
2022-11-15 CVE-2022-45402 Unspecified vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
network
low complexity
apache
6.1
2022-11-02 CVE-2022-43670 Unspecified vulnerability in Apache Sling CMS
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management feature.
network
low complexity
apache
5.4
2022-11-02 CVE-2022-43982 Cross-site Scripting vulnerability in Apache Airflow
In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument.
network
low complexity
apache CWE-79
6.1