Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-19 CVE-2021-39234 Incorrect Authorization vulnerability in Apache Ozone
In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL.
network
high complexity
apache CWE-863
6.8
2021-11-19 CVE-2021-39235 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Ozone
In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token.
network
low complexity
apache CWE-732
6.5
2021-11-19 CVE-2021-41532 Unspecified vulnerability in Apache Ozone
In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata.
network
low complexity
apache
5.3
2021-11-17 CVE-2021-42250 Improper Encoding or Escaping of Output vulnerability in Apache Superset
Improper output neutralization for Logs.
network
low complexity
apache CWE-116
6.5
2021-11-12 CVE-2021-41972 Unspecified vulnerability in Apache Superset
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users.
network
low complexity
apache
6.5
2021-11-01 CVE-2021-41973 Infinite Loop vulnerability in multiple products
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely.
network
low complexity
apache oracle CWE-835
6.5
2021-10-18 CVE-2021-32609 Cross-site Scripting vulnerability in Apache Superset
Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page.
network
low complexity
apache CWE-79
5.4
2021-10-12 CVE-2021-42009 Improper Input Validation vulnerability in Apache Traffic Control
An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Traffic Ops endpoint to send an email, from the Traffic Ops server, with an arbitrary body to an arbitrary email address.
network
low complexity
apache CWE-20
4.3
2021-10-11 CVE-2021-41831 Improper Verification of Cryptographic Signature vulnerability in Apache Openoffice
It is possible for an attacker to manipulate the timestamp of signed documents.
network
low complexity
apache CWE-347
5.3
2021-10-07 CVE-2021-40439 XXE vulnerability in Apache Openoffice
Apache OpenOffice has a dependency on expat software.
network
low complexity
apache CWE-611
6.5