Vulnerabilities > Apache > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-25 CVE-2017-15703 Deserialization of Untrusted Data vulnerability in Apache Nifi
Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack.
local
low complexity
apache CWE-502
5.0
2018-01-19 CVE-2017-15713 Information Exposure vulnerability in Apache Hadoop
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process.
network
low complexity
apache CWE-200
6.5
2018-01-10 CVE-2016-6810 Cross-site Scripting vulnerability in Apache Activemq
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console.
network
low complexity
apache CWE-79
6.1
2018-01-10 CVE-2017-15717 Cross-site Scripting vulnerability in Apache products
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads.
network
low complexity
apache CWE-79
6.1
2018-01-10 CVE-2017-9796 Information Exposure vulnerability in Apache Geode
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
network
high complexity
apache CWE-200
5.3
2018-01-04 CVE-2017-17837 Cross-site Scripting vulnerability in Apache Deltaspike 1.8.0
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling.
network
low complexity
apache CWE-79
6.1
2017-12-18 CVE-2017-12630 Cross-site Scripting vulnerability in Apache Drill
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards.
network
low complexity
apache CWE-79
5.4
2017-12-01 CVE-2017-15707 Improper Input Validation vulnerability in multiple products
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
local
low complexity
apache netapp oracle CWE-20
6.2
2017-11-20 CVE-2017-3157 Information Exposure vulnerability in multiple products
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem.
local
low complexity
apache debian redhat CWE-200
5.5
2017-11-15 CVE-2014-0219 Improper Input Validation vulnerability in Apache Karaf
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
local
low complexity
apache CWE-20
5.5