Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-05 CVE-2021-27907 Cross-site Scripting vulnerability in Apache Superset
Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information.
network
low complexity
apache CWE-79
5.4
2021-03-02 CVE-2020-1936 Cross-site Scripting vulnerability in Apache Ambari
A cross-site scripting issue was found in Apache Ambari Views.
network
low complexity
apache CWE-79
6.1
2021-03-01 CVE-2020-9479 Path Traversal vulnerability in Apache Asterixdb
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory.
local
low complexity
apache CWE-22
5.5
2021-02-26 CVE-2020-27223 Resource Exhaustion vulnerability in multiple products
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e.
network
low complexity
eclipse apache netapp debian oracle CWE-400
5.3
2021-02-20 CVE-2021-26544 Cross-site Scripting vulnerability in Apache Livy 0.7.0Incubating
Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name.
network
low complexity
apache CWE-79
5.4
2021-02-17 CVE-2021-26697 Missing Authentication for Critical Function vulnerability in Apache Airflow 2.0.0
The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0.
network
low complexity
apache CWE-306
5.3
2021-02-17 CVE-2021-26559 Unspecified vulnerability in Apache Airflow 2.0.0
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`.
network
low complexity
apache
6.5
2021-02-08 CVE-2020-13947 Cross-site Scripting vulnerability in multiple products
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
network
low complexity
apache oracle CWE-79
6.1
2021-01-26 CVE-2020-17522 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Traffic Control
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers.
network
low complexity
apache CWE-732
5.8
2021-01-19 CVE-2020-11997 Incorrect Default Permissions vulnerability in Apache Guacamole
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility.
network
low complexity
apache CWE-276
4.3