apache

2,899 tracked vulnerabilities.

CVE-2023-42503 MEDIUM
Apache Commons Compress 1.22-1.23.0 - Denial of Service via Malformed TAR File Modification Time Headers
Sep 14, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-41267 HIGH
Apache Airflow HDFS Provider <4.1.1 - Info Disclosure
Sep 14, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-41081 HIGH
Apache Tomcat Connectors - Auth Bypass
Sep 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-40712 MEDIUM
Apache Airflow <2.7.1 - Info Disclosure
Sep 12, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-40611 MEDIUM
Apache Airflow <2.7.1 - Privilege Escalation
Sep 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-39265 LOW
Apache Superset <= 2.1.0 - SQLite Database Connection Manipulation via Alternative Driver Names
Sep 06, 2023
CVSS 3.8
EPSS 0.72
CVE-2023-37941 MEDIUM
Apache Superset 1.5.0-2.1.0 - Remote Code Execution via Metadata Database Deserialization
Sep 06, 2023
CVSS 6.6
EPSS 0.84
CVE-2023-32672 MEDIUM
Apache Superset <= 2.1.0 - Authenticated Incorrect Authorization in SQLLab
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-39264 MEDIUM
Apache Superset <= 2.1.0 - Sensitive Information Exposure via REST API Error Stack Traces
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-36388 MEDIUM
Apache Superset <= 2.1.0 - Authenticated Server-Side Request Forgery via Network Connection Test
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-36387 MEDIUM
Apache Superset <2.1.0 - Info Disclosure
Sep 06, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-27526 MEDIUM
Apache Superset <= 2.1.0 - Authenticated Incorrect Authorization via Import Charts Feature
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-27523 MEDIUM
Apache Superset <= 2.1.0 - Authenticated Improper Data Authorization in Jinja Templated Queries
Sep 06, 2023
CVSS 5.0
EPSS 0.00
CVE-2023-40743 CRITICAL
Apache Axis 1.x - Server-Side Request Forgery and Remote Code Execution via ServiceFactory.getService
Sep 05, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-41180 MEDIUM
Apache NiFi MiNiFi C++ <0.15 - Certificate Validation
Sep 03, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-40195 HIGH
Apache Airflow Spark Provider < 4.1.3 - Authenticated Remote Code Execution via Malicious Spark Server
Aug 28, 2023
CVSS 8.8
EPSS 0.03
CVE-2023-27604 HIGH
Apache Airflow Sqoop Provider < 4.0.0 - Authenticated Remote Code Execution via Sqoop Import Connection Parameters
Aug 28, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-41080 MEDIUM
Apache Tomcat <11.0.0-M10 - Open Redirect
Aug 25, 2023
CVSS 6.1
EPSS 0.12
CVE-2023-40273 HIGH
Apache Airflow < 2.7.0 - Authenticated Session Fixation via Password Reset
Aug 23, 2023
CVSS 8.0
EPSS 0.00
CVE-2023-39441 MEDIUM
Apache Airflow < 2.7.0 - Improper Certificate Validation
Aug 23, 2023
CVSS 5.9
EPSS 0.00
CVE-2023-37379 HIGH
Apache Airflow < 2.7.0 - Authenticated Denial of Service via Connection Test Feature
Aug 23, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-40037 MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
Aug 18, 2023
CVSS 6.5
EPSS 0.01
CVE-2023-40272 HIGH
Apache Airflow Spark Provider < 4.1.3 - Arbitrary File Read via Connection Parameters
Aug 17, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-39553 HIGH
Apache Airflow Drill Provider < 2.4.3 - Unauthenticated Arbitrary File Read via DrillHook Connection Parameters
Aug 11, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-33934 CRITICAL
Apache Traffic Server <9.2.1 - Info Disclosure
Aug 09, 2023
CVSS 9.1
EPSS 0.00