Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 1771

Browse all 1771 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2024-38856 Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code — Apache OFBizCWE-863 5.6AIMediumAI2024-08-05
CVE-2024-42447 Apache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow — Apache Airflow Providers FABCWE-613 9.1AICriticalAI2024-08-05
CVE-2024-36268 Apache InLong TubeMQ Client: Remote Code Execution vulnerability — Apache InLong TubeMQ ClientCWE-94 9.8AICriticalAI2024-08-02
CVE-2024-27182 Apache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerability — Apache Linkis Basic management servicesCWE-552 6.5AIMediumAI2024-08-02
CVE-2024-27181 Apache Linkis Basic management services: Privilege Escalation Attack vulnerability — Apache Linkis Basic management servicesCWE-269 6.5AIMediumAI2024-08-02
CVE-2023-48396 Apache SeaTunnel Web: Authentication bypass — Apache SeaTunnel WebCWE-290 9.8AICriticalAI2024-07-30
CVE-2023-38522 Apache Traffic Server: Incomplete field name check allows request smuggling — Apache Traffic ServerCWE-444 5.3 -2024-07-26
CVE-2024-35296 Apache Traffic Server: Invalid Accept-Encoding can force forwarding requests — Apache Traffic ServerCWE-20 5.3 -2024-07-26
CVE-2024-35161 Apache Traffic Server: Incomplete check for chunked trailer section allows request smuggling — Apache Traffic ServerCWE-444 5.3 -2024-07-26
CVE-2024-25090 Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode — Apache RollerCWE-20 5.4 -2024-07-26
CVE-2023-48362 Apache Drill: XXE Vulnerability in XML Format Reader — Apache DrillCWE-611 8.8AIHighAI2024-07-24
CVE-2024-39676 Apache Pinot: Unauthorized endpoint exposed sensitive information — Apache PinotCWE-200 5.3AIMediumAI2024-07-24
CVE-2024-41178 Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files — Apache Arrow Rust Object StoreCWE-532 8.1AIHighAI2024-07-23
CVE-2024-29070 Apache StreamPark: session not invalidated after logout — Apache StreamParkCWE-613 6.5AIMediumAI2024-07-23
CVE-2024-34457 Apache StreamPark IDOR Vulnerability — Apache StreamParkCWE-639 6.5AIMediumAI2024-07-22
CVE-2024-38503 Apache Syncope: HTML tags can be injected into Console or Enduser text fields — Apache SyncopeCWE-79 5.4AIMediumAI2024-07-22
CVE-2024-23321 Apache RocketMQ: Unauthorized Exposure of Sensitive Data — Apache RocketMQCWE-200 8.8AIHighAI2024-07-22
CVE-2024-41107 Apache CloudStack: SAML Signature Exclusion — Apache CloudStackCWE-290 9.8 -2024-07-19
CVE-2024-41172 Apache CXF: Unrestricted memory consumption in CXF HTTP clients — Apache CXFCWE-401 7.5 -2024-07-19
CVE-2024-32007 Apache CXF Denial of Service vulnerability in JOSE — Apache CXFCWE-400 7.5 -2024-07-19
CVE-2024-29736 Apache CXF: SSRF vulnerability via WADL stylesheet parameter — Apache CXFCWE-918 9.1 -2024-07-19
CVE-2024-29178 Apache StreamPark: FreeMarker SSTI RCE Vulnerability — Apache StreamParkCWE-94 8.8AIHighAI2024-07-18
CVE-2024-40725 Apache HTTP Server: source code disclosure with handlers configured via AddType — Apache HTTP ServerCWE-668 7.5 -2024-07-18
CVE-2024-40898 Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows — Apache HTTP ServerCWE-918 7.5AIHighAI2024-07-18
CVE-2024-29120 Apache StreamPark: Information leakage vulnerability — Apache StreamParkCWE-212 8.8AIHighAI2024-07-17
CVE-2024-31411 Apache StreamPipes: Potential remote code execution (RCE) via file upload — Apache StreamPipesCWE-434 8.8AIHighAI2024-07-17
CVE-2024-31979 Apache StreamPipes: Possibility of SSRF in pipeline element installation process — Apache StreamPipesCWE-918 8.1AIHighAI2024-07-17
CVE-2024-30471 Apache StreamPipes: Potential creation of multiple identical accounts — Apache StreamPipesCWE-367 7.4AIHighAI2024-07-17
CVE-2024-29737 Apache StreamPark (incubating): maven build params could trigger remote command execution — Apache StreamPark (incubating)CWE-77 8.8AIHighAI2024-07-17
CVE-2023-52291 Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution — Apache StreamPark (incubating)CWE-77 8.8AIHighAI2024-07-17

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.