VYPR

Vendor CVEs

Apache

All CVEs

3,418 total · sorted by risk
  • CVE-2024-29834MedApr 2, 2024
    risk 0.35cvss 6.4epss 0.01

    This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These management operations should be restricted to users with the tenant admin role or…

  • CVE-2024-27140MedMar 1, 2024
    risk 0.35cvss 5.4epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a version that fixes this…

  • CVE-2024-23946MedFeb 29, 2024
    risk 0.35cvss 5.3epss 0.03

    Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

  • CVE-2023-50380MedFeb 27, 2024
    risk 0.35cvss 6.5epss 0.01

    XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from…

  • CVE-2024-23349MedFeb 22, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters summary. A logged-in user, when modifying their own submitted question, can input…

  • CVE-2023-50270MedFeb 20, 2024
    risk 0.35cvss 6.5epss 0.01

    Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

  • CVE-2023-39196MedFeb 7, 2024
    risk 0.35cvss 5.3epss 0.01

    Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication. The attacker is not allowed to do any modification within the Ozone Storage…

  • CVE-2023-51702MedJan 24, 2024
    risk 0.35cvss 6.5epss 0.00

    Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption.…

  • CVE-2023-50944MedJan 24, 2024
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to…

  • CVE-2023-50783MedDec 21, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.8.0, is affected by a vulnerability that allows an authenticated user without the variable edit permission, to update a variable. This flaw compromises the integrity of variable management, potentially leading to unauthorized data modification.…

  • CVE-2023-49920MedDec 21, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airflow UI opened - to…

  • CVE-2023-49736MedDec 19, 2023
    risk 0.35cvss 6.5epss 0.01

    A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version…

  • CVE-2023-46104MedDec 19, 2023
    risk 0.35cvss 6.5epss 0.02

    Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.   This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.

  • CVE-2023-49620MedNov 30, 2023
    risk 0.35cvss 6.5epss 0.01

    Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level…

  • CVE-2023-42781MedNov 12, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs.  This is a different issue than CVE-2023-42663 but leading to similar outcome. Users of…

  • CVE-2023-46819MedNov 7, 2023
    risk 0.35cvss 5.3epss 0.02

    Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Users are recommended to upgrade to version 18.12.09

  • CVE-2023-25753MedOct 19, 2023
    risk 0.35cvss 6.5epss 0.01

    There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl parameter. Of particular…

  • CVE-2023-43666MedOct 16, 2023
    risk 0.35cvss 6.5epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve…

  • CVE-2023-42792MedOct 14, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could give the user write access to various DAG resources for DAGs that the user had no access to, thus,…

  • CVE-2023-42780MedOct 14, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs. It would reveal the dag_ids and the stack-traces of import errors for those…

  • CVE-2023-42663MedOct 14, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the…

  • CVE-2023-40712MedSep 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. …

  • CVE-2023-40037MedAug 18, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL…

  • CVE-2023-37581MedAug 6, 2023
    risk 0.35cvss 5.4epss 0.01

    Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted…

  • CVE-2023-34189MedJul 25, 2023
    risk 0.35cvss 6.5epss 0.01

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  …

  • CVE-2023-36543MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected

  • CVE-2023-35908MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows unauthorized read access to a DAG through the URL. It is recommended to upgrade to a version that is not affected

  • CVE-2023-22888MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to cause a service disruption by manipulating the run_id parameter. This vulnerability is considered low since it requires an authenticated user to exploit it. It is recommended to…

  • CVE-2023-22887MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.02

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized file access outside the intended directory structure by manipulating the run_id parameter. This vulnerability is considered low since it requires an…

  • CVE-2022-46651MedJul 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection resources…

  • CVE-2023-35005MedJun 19, 2023
    risk 0.35cvss 6.5epss 0.02

    In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerability is mitigated by the fact configuration is not shown in the UI by default (only if `[webserver] expose_config` is set to `non-sensitive-only`), and not all…

  • CVE-2023-34212MedJun 12, 2023
    risk 0.35cvss 6.5epss 0.02

    The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from…

  • CVE-2023-31101MedMay 22, 2023
    risk 0.35cvss 6.5epss 0.01

    Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache…

  • CVE-2022-45801MedMay 1, 2023
    risk 0.35cvss 5.4epss 0.01

    Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP…

  • CVE-2023-22665MedApr 25, 2023
    risk 0.35cvss 5.4epss 0.01

    There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.

  • CVE-2023-22946MedApr 17, 2023
    risk 0.35cvss 6.4epss 0.01

    In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application can execute code with the privileges of the submitting user, however, by providing malicious configuration-related classes on the…

  • CVE-2023-28158MedMar 29, 2023
    risk 0.35cvss 6.5epss 0.01

    Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.

  • CVE-2023-25621MedFeb 23, 2023
    risk 0.35cvss 6.5epss 0.01

    Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it allows an author to…

  • CVE-2022-45438MedJan 16, 2023
    risk 0.35cvss 5.3epss 0.01

    When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and…

  • CVE-2022-43721MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

  • CVE-2022-43720MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2…

  • CVE-2022-43718MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

  • CVE-2022-43717MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and…

  • CVE-2022-41703MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user…

  • CVE-2022-46769MedJan 9, 2023
    risk 0.35cvss 5.4epss 0.01

    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in the site group feature. …

  • CVE-2022-46870MedDec 16, 2022
    risk 0.35cvss 5.4epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. Users are recommended to…

  • CVE-2022-45910MedDec 7, 2022
    risk 0.35cvss 5.3epss 0.01

    Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries,…

  • CVE-2021-37533MedDec 3, 2022
    risk 0.35cvss 6.5epss 0.02

    Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of…

  • CVE-2022-43670MedNov 2, 2022
    risk 0.35cvss 5.4epss 0.01

    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.0 and prior may allow an authenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the taxonomy management…

  • CVE-2022-26884MedOct 28, 2022
    risk 0.35cvss 6.5epss 0.02

    Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

Page 43 of 69