Apache
apache
3,377 CVEs • 392 products
Products (392)
Click to collapseToggle
Products (392)
Click to collapse
CVEs (3,377)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications. |
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0...Show more |
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0...Show more |
Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose private files owned by the user running the MapReduce job history server pr...Show more |
A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap. Such overlapping writes could cause packet data to be misread as the...Show more |
2Apache Redhat2Enterprise Linux Server GroovyNov 21, 2024 Jan 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store...Show more |
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output va...Show more |
1Apache 2Sling Xss Protection Api Sling Xss Protection Api CompatNov 21, 2024 Jan 10, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they...Show more |
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow r...Show more |
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to objects within unauth...Show more |
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status information and control cluste...Show more |
1Apache 1Sling Jcr Contentloader Nov 21, 2024 Jan 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information l...Show more |
The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied...Show more |
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert...Show more |
2Apache Hp2Flex Blazeds Xp Command View Advanced EditionMay 13, 2026 Dec 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several kn...Show more |
1Apache 1Sling Authentication Service May 13, 2026 Dec 18, 2017 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials. |
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that ret...Show more |
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch'...Show more |
2Apache Oracle3Financial Services Market Risk Measurement And Management Peoplesoft Enterprise PeopletoolsSynapseMay 13, 2026 Dec 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution...Show more |
3Apache NetappOracle12Agile Plm Framework Enterprise Manager For VirtualizationFinancial Services Hedge Management And Ifrs Valuations+9 moreMay 13, 2026 Dec 1, 2017 N/A· v4 6.2 MEDIUM· v3 5.0 MEDIUM· v2 In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload. |