VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2022-31780HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-31779HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-31778HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2.

  • CVE-2022-28129HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2021-37150HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-36125HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.01

    It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

  • CVE-2022-36124HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.01

    It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version…

  • CVE-2022-35724HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.02

    It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which…

  • CVE-2022-24294HigJul 24, 2022
    risk 0.49cvss 7.5epss 0.02

    A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug could be exploited when loading a model in Apache MXNet that has a specially crafted operator name that would cause the regular…

  • CVE-2022-36127HigJul 18, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection.

  • CVE-2021-34538HigJul 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized…

  • CVE-2022-26477HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.02

    The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and write logic. We…

  • CVE-2022-30556HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.05

    Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.

  • CVE-2022-29404HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.06

    In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

  • CVE-2022-26650HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters…

  • CVE-2022-29265HigApr 30, 2022
    risk 0.49cvss 7.5epss 0.03

    Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors…

  • CVE-2022-23942HigApr 26, 2022
    risk 0.49cvss 7.5epss 0.03

    Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

  • CVE-2022-29266HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.08

    In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.

  • CVE-2022-24070HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.09

    Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do…

  • CVE-2022-25598HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

  • CVE-2021-44040HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

  • CVE-2022-26779HigMar 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is…

  • CVE-2021-38296HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for full encryption key recovery. After an initial interactive…

  • CVE-2022-23913HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

  • CVE-2021-40110HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which…

  • CVE-2021-34797HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.03

    Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or…

  • CVE-2021-41561HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

  • CVE-2021-26558HigNov 11, 2021
    risk 0.49cvss 7.5epss 0.02

    Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apache ShardingSphere-UI Apache ShardingSphere-UI version 4.1.1 and later versions; Apache ShardingSphere-UI versions prior to 5.0.0.

  • CVE-2021-41585HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to make the server stop accepting new connections. This issue affects Apache Traffic Server 5.0.0 to 9.1.0.

  • CVE-2021-37149HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

  • CVE-2021-37148HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.0.1.

  • CVE-2021-37147HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.02

    Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

  • CVE-2021-41832HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.01

    It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.

  • CVE-2021-41830HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.01

    It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory.

  • CVE-2021-36749MedSep 24, 2021
    risk 0.49cvss 6.5epss 0.81

    In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server…

  • CVE-2021-39239HigSep 16, 2021
    risk 0.49cvss 7.5epss 0.04

    A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

  • CVE-2020-13929HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.03

    Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.

  • CVE-2021-33580HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.03

    User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. Since the attacker…

  • CVE-2021-33900HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not…

  • CVE-2021-28131HigJul 22, 2021
    risk 0.49cvss 7.5epss 0.03

    Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala logs, therefore Impala users with access to the logs can use another authenticated user's sessions with specially constructed…

  • CVE-2021-30639HigJul 12, 2021
    risk 0.49cvss 7.5epss 0.07

    A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests.…

  • CVE-2021-32567HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-32566HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-32565HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.02

    Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-27577HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.04

    Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

  • CVE-2021-30468HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.07

    A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache…

  • CVE-2021-27737HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.04

    Apache Traffic Server 9.0.0 is vulnerable to a remote DOS attack on the experimental Slicer plugin.

  • CVE-2021-31164HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.02

    Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

  • CVE-2021-30638HigApr 27, 2021
    risk 0.49cvss 7.5epss 0.07

    Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry…

  • CVE-2020-17517HigApr 27, 2021
    risk 0.49cvss 7.5epss 0.02

    The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to…

Page 22 of 69