Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2021-36151 Information Exposure vulnerability in Apache Gobblin 0.15.0
In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems.
local
low complexity
apache CWE-200
5.5
2022-02-01 CVE-2021-44451 Insufficiently Protected Credentials vulnerability in Apache Superset
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users.
network
low complexity
apache CWE-522
6.5
2022-02-01 CVE-2021-41571 Incorrect Authorization vulnerability in Apache Pulsar
In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user.
network
low complexity
apache CWE-863
6.5
2022-01-26 CVE-2022-22932 Path Traversal vulnerability in Apache Karaf
Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder.
network
low complexity
apache CWE-22
5.3
2022-01-24 CVE-2022-23437 Infinite Loop vulnerability in multiple products
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads.
network
low complexity
apache oracle netapp CWE-835
6.5
2022-01-20 CVE-2021-45230 Unspecified vulnerability in Apache Airflow
In Apache Airflow prior to 2.2.0.
network
low complexity
apache
6.5
2022-01-20 CVE-2022-22733 Information Exposure vulnerability in Apache Shardingsphere Elasticjob-Ui 3.0.0
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation.
network
low complexity
apache CWE-200
6.5
2022-01-17 CVE-2021-42357 Cross-site Scripting vulnerability in Apache Knox
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing.
network
low complexity
apache CWE-79
6.1
2022-01-11 CVE-2021-41767 Information Exposure vulnerability in Apache Guacamole
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some REST responses.
network
low complexity
apache CWE-200
6.5
2022-01-06 CVE-2021-36774 Unspecified vulnerability in Apache Kylin
Apache Kylin allows users to read data from other database systems using JDBC.
network
low complexity
apache
6.5