Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-08-04 CVE-2022-28731 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
network
low complexity
apache CWE-352
6.5
2022-08-04 CVE-2022-28732 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-07-07 CVE-2021-44791 Cross-site Scripting vulnerability in Apache Druid
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses.
network
low complexity
apache CWE-79
6.1
2022-07-07 CVE-2022-28889 Improper Restriction of Rendered UI Layers or Frames vulnerability in Apache Druid
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking.
network
low complexity
apache CWE-1021
4.3
2022-07-06 CVE-2021-37839 Improper Check for Dropped Privileges vulnerability in Apache Superset
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on.
network
low complexity
apache CWE-273
4.3
2022-06-23 CVE-2022-34305 Cross-site Scripting vulnerability in Apache Tomcat
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
network
low complexity
apache CWE-79
6.1
2022-06-22 CVE-2022-32549 Improper Encoding or Escaping of Output vulnerability in Apache Sling API and Sling Commons LOG
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection.
network
low complexity
apache CWE-116
5.3
2022-06-09 CVE-2022-28330 Out-of-bounds Read vulnerability in Apache Http Server
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
network
low complexity
apache CWE-125
5.3
2022-06-09 CVE-2022-28614 Integer Overflow or Wraparound vulnerability in multiple products
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function.
network
low complexity
apache fedoraproject netapp CWE-190
5.3
2022-06-09 CVE-2022-24969 Server-Side Request Forgery (SSRF) vulnerability in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
network
low complexity
apache CWE-918
6.1