VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2020-9491HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and…

  • CVE-2020-9487HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly…

  • CVE-2020-9486HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.04

    In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

  • CVE-2020-11979HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.08

    As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively…

  • CVE-2020-1942HigFeb 11, 2020
    risk 0.42cvss 7.5epss 0.03

    In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and…

  • CVE-2020-1932MedJan 28, 2020
    risk 0.42cvss 6.5epss 0.01

    An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.

  • CVE-2020-1929HigJan 15, 2020
    risk 0.42cvss 7.5epss 0.01

    The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally…

  • CVE-2019-19906HigDec 19, 2019
    risk 0.42cvss 7.5epss 0.08

    cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.

  • CVE-2019-12420HigDec 12, 2019
    risk 0.42cvss 7.5epss 0.07

    In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.

  • CVE-2009-5004MedNov 9, 2019
    risk 0.42cvss 6.5epss 0.03

    qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

  • CVE-2019-0210HigOct 29, 2019
    risk 0.42cvss 7.5epss 0.07

    In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

  • CVE-2019-10079HigOct 22, 2019
    risk 0.42cvss 7.5epss 0.05

    Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions.

  • CVE-2018-11782MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.02

    In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

  • CVE-2017-15694MedJun 21, 2019
    risk 0.42cvss 6.5epss 0.02

    When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.

  • CVE-2018-20245HigJan 23, 2019
    risk 0.42cvss 7.5epss 0.01

    The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checking.

  • CVE-2018-1000421MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained…

  • CVE-2018-1000420MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

  • CVE-2018-1320HigJan 7, 2019
    risk 0.42cvss 7.5epss 0.08

    Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production…

  • CVE-2018-11799MedDec 19, 2018
    risk 0.42cvss 6.5epss 0.01

    Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.

  • CVE-2018-17195HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.01

    The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication,…

  • CVE-2018-17194HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait…

  • CVE-2018-11785MedOct 24, 2018
    risk 0.42cvss 6.5epss 0.01

    Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.

  • CVE-2018-11763MedSep 25, 2018
    risk 0.42cvss 5.9epss 0.51

    In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2…

  • CVE-2018-11775HigSep 10, 2018
    risk 0.42cvss 7.4epss 0.07

    TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

  • CVE-2018-8030HigJun 20, 2018
    risk 0.42cvss 7.5epss 0.04

    A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP…

  • CVE-2018-1332MedJun 5, 2018
    risk 0.42cvss 6.5epss 0.01

    Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.

  • CVE-2018-8015HigMay 18, 2018
    risk 0.42cvss 7.5epss 0.03

    In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, the stack overflow might…

  • CVE-2018-1327HigMar 27, 2018
    risk 0.42cvss 7.5epss 0.09

    The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described…

  • CVE-2018-1286MedFeb 28, 2018
    risk 0.42cvss 6.5epss 0.01

    In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.

  • CVE-2009-4267MedFeb 19, 2018
    risk 0.42cvss 6.5epss 0.01

    The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.

  • CVE-2017-15712MedFeb 19, 2018
    risk 0.42cvss 6.5epss 0.03

    Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie…

  • CVE-2017-15713MedJan 19, 2018
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server process. The malicious user can construct a configuration…

  • CVE-2017-15701HigDec 1, 2017
    risk 0.42cvss 7.5epss 0.04

    In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older…

  • CVE-2014-0072HigOct 30, 2017
    risk 0.42cvss 7.5epss 0.08

    ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow remote attackers to spoof SSL servers by leveraging a default…

  • CVE-2015-0226HigOct 30, 2017
    risk 0.42cvss 7.5epss 0.06

    Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted…

  • CVE-2016-6815MedOct 13, 2017
    risk 0.42cvss 6.5epss 0.02

    In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.

  • CVE-2017-12623MedOct 10, 2017
    risk 0.42cvss 6.5epss 0.02

    An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a prior 1.x release should…

  • CVE-2017-9792MedOct 4, 2017
    risk 0.42cvss 6.5epss 0.02

    In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to point to other Kudu tables.…

  • CVE-2017-9797MedOct 3, 2017
    risk 0.42cvss 6.5epss 0.01

    When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In addition, an attacker could…

  • CVE-2017-9790HigSep 29, 2017
    risk 0.42cvss 7.5epss 0.02

    When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with '/'. A malicious…

  • CVE-2017-7687HigSep 29, 2017
    risk 0.42cvss 7.5epss 0.02

    When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious actor can therefore…

  • CVE-2017-9804HigSep 20, 2017
    risk 0.42cvss 7.5epss 0.08

    In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. …

  • CVE-2014-7808HigSep 15, 2017
    risk 0.42cvss 7.5epss 0.01

    Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.

  • CVE-2015-3250HigSep 7, 2017
    risk 0.42cvss 7.5epss 0.05

    Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.

  • CVE-2016-6796HigAug 11, 2017
    risk 0.42cvss 7.5epss 0.08

    A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

  • CVE-2016-6817HigAug 10, 2017
    risk 0.42cvss 7.5epss 0.07

    The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

  • CVE-2016-6797HigAug 10, 2017
    risk 0.42cvss 7.5epss 0.08

    The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application.…

  • CVE-2017-3156HigAug 10, 2017
    risk 0.42cvss 7.5epss 0.06

    The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

  • CVE-2016-8739HigAug 10, 2017
    risk 0.42cvss 7.5epss 0.07

    The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

  • CVE-2011-4343HigAug 8, 2017
    risk 0.42cvss 7.5epss 0.05

    Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.

Page 35 of 69