VYPR

Apache

by Apache

Source repositories

CVEs (202)

  • CVE-2024-23953MedJan 28, 2025
    risk 0.35cvss 6.5epss 0.01

    Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are recommended to…

  • CVE-2023-40037MedAug 18, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL…

  • CVE-2023-34212MedJun 12, 2023
    risk 0.35cvss 6.5epss 0.02

    The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from…

  • CVE-2023-22665MedApr 25, 2023
    risk 0.35cvss 5.4epss 0.01

    There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.

  • CVE-2018-17192MedDec 19, 2018
    risk 0.35cvss 6.5epss 0.03

    The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security…

  • CVE-2016-8748MedOct 19, 2017
    risk 0.35cvss 5.4epss 0.02

    In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.

  • CVE-2025-66249MedMar 13, 2026
    risk 0.34cvss 6.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration…

  • CVE-2025-60012MedMar 13, 2026
    risk 0.34cvss 6.3epss 0.00

    Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to…

  • CVE-2022-42466MedOct 19, 2022
    risk 0.33cvss 6.1epss 0.01

    Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed.…

  • CVE-2018-17193MedDec 19, 2018
    risk 0.33cvss 6.1epss 0.03

    The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release.…

  • CVE-2012-3536MedFeb 27, 2018
    risk 0.33cvss 6.1epss 0.02

    Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a carefully crafted email to a user of Hupa which would trigger a XSS when the email was opened or when a list of messages were…

  • CVE-2016-6812MedAug 10, 2017
    risk 0.33cvss 6.1epss 0.09

    The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current…

  • CVE-2024-52012MedJan 27, 2025
    risk 0.32cvss 5.4epss 0.47

    Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API.  Commonly known as a "zipslip", maliciously constructed ZIP files can use…

  • CVE-2025-23184MedJan 21, 2025
    risk 0.32cvss 5.9epss 0.02

    A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and…

  • CVE-2024-23945MedDec 23, 2024
    risk 0.31cvss 5.9epss 0.02

    Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation.…

  • CVE-2025-48795MedJul 15, 2025
    risk 0.29cvss 5.6epss 0.01

    Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing…

  • CVE-2024-29869MedJan 28, 2025
    risk 0.29cvss 5.5epss 0.00

    Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users…

  • CVE-2025-24814MedJan 27, 2025
    risk 0.29cvss 5.5epss 0.01

    Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization…

  • CVE-2022-30973MedMay 31, 2022
    risk 0.29cvss 5.5epss 0.02

    We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted…

  • CVE-2022-30126MedMay 16, 2022
    risk 0.29cvss 5.5epss 0.03

    In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler,…

Page 8 of 11