Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-14 CVE-2024-25142 Unspecified vulnerability in Apache Airflow
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.
local
low complexity
apache
5.5
2024-05-14 CVE-2024-32077 Unspecified vulnerability in Apache Airflow 2.9.0
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.
network
low complexity
apache
5.4
2024-05-07 CVE-2024-28148 Unspecified vulnerability in Apache Superset
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
network
low complexity
apache
4.3
2024-04-18 CVE-2024-31869 Unspecified vulnerability in Apache Airflow
Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the "configuration" UI page when "non-sensitive-only" was set as "webserver.expose_config" configuration (The celery provider is the only community provider currently that has sensitive configurations).
network
low complexity
apache
4.3
2024-04-09 CVE-2024-31863 Unspecified vulnerability in Apache Zeppelin 0.10.1
Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue.
network
low complexity
apache
5.3
2024-04-02 CVE-2024-29834 Unspecified vulnerability in Apache Pulsar
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction.
network
low complexity
apache
6.4
2024-03-12 CVE-2024-28098 Unspecified vulnerability in Apache Pulsar
The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings.
network
low complexity
apache
5.4
2024-02-29 CVE-2024-23946 Unspecified vulnerability in Apache Ofbiz
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
network
low complexity
apache
5.3
2024-02-28 CVE-2024-24772 SQL Injection vulnerability in Apache Superset
A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
network
low complexity
apache CWE-89
4.3
2024-02-28 CVE-2024-24773 Incorrect Authorization vulnerability in Apache Superset
Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which fixes the issue.
network
low complexity
apache CWE-863
6.5