Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 1803

Browse all 1803 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2023-46589 Apache Tomcat: HTTP request smuggling via malformed trailer headers — Apache TomcatCWE-444 7.5 -2023-11-28
CVE-2022-41678 Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE — Apache ActiveMQCWE-287 8.8 -2023-11-28
CVE-2023-49145 Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt — Apache NiFiCWE-79 7.9 High2023-11-27
CVE-2023-43701 Apache Superset: Stored XSS on API endpoint — Apache SupersetCWE-79 4.3 Medium2023-11-27
CVE-2023-42501 Apache Superset: Unnecessary read permissions within the Gamma role — Apache SupersetCWE-276 4.3 Medium2023-11-27
CVE-2023-40610 Apache Superset: Privilege escalation with default examples database — Apache SupersetCWE-863 6.3 Medium2023-11-27
CVE-2023-49068 Apache DolphinScheduler: Information Leakage Vulnerability — Apache DolphinSchedulerCWE-200 7.5 -2023-11-27
CVE-2023-48796 Apache dolphinscheduler sensitive information disclosure — Apache DolphinSchedulerCWE-200 7.5 -2023-11-24
CVE-2023-43123 Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files — Apache StormCWE-200 5.5 -2023-11-23
CVE-2023-37924 Apache Submarine: SQL injection from unauthorized login — Apache SubmarineCWE-89 8.8AIHighAI2023-11-22
CVE-2022-46337 Apache Derby: LDAP injection vulnerability in authenticator — Apache Derby 9.8AICriticalAI2023-11-20
CVE-2023-46302 Apache Submarine: Fix CVE-2022-1471 SnakeYaml unsafe deserialization — Apache SubmarineCWE-502 9.8AICriticalAI2023-11-20
CVE-2023-26031 Privilege escalation in Apache Hadoop Yarn container-executor binary on Linux systems — Apache HadoopCWE-426 7.8 -2023-11-16
CVE-2023-42781 Apache Airflow: Permission verification bypass allows viewing dagruns of other dags — Apache AirflowCWE-200 4.3 -2023-11-12
CVE-2023-47037 Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access) — Apache AirflowCWE-863 5.4 -2023-11-12
CVE-2023-47248 PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file — PyArrowCWE-502 9.8 -2023-11-09
CVE-2023-39913 Apache UIMA Java SDK Core, Apache UIMA Java SDK CPE, Apache UIMA Java SDK Vinci adapter, Apache UIMA Java SDK tools: Potential untrusted code execution when deserializing certain binary CAS formats — Apache UIMA Java SDK CoreCWE-502 9.8 -2023-11-08
CVE-2023-46819 Apache OFBiz: Execution of Solr plugin queries without authentication — Apache OFBizCWE-306 9.8 -2023-11-07
CVE-2023-46851 Apache Allura: sensitive information exposure via import — Apache AlluraCWE-20 9.8 -2023-11-07
CVE-2023-46215 Apache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend — Apache Airflow Celery providerCWE-532 7.5 -2023-10-28
CVE-2023-46604 Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack — Apache ActiveMQCWE-502 10.0 Critical2023-10-27
CVE-2023-46288 Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set — Apache AirflowCWE-200 4.3 -2023-10-23
CVE-2023-31122 Apache HTTP Server: mod_macro buffer over-read — Apache HTTP ServerCWE-125 7.5 -2023-10-23
CVE-2023-43622 Apache HTTP Server: DoS in HTTP/2 with initial windows size 0 — Apache HTTP ServerCWE-400 7.5 -2023-10-23
CVE-2023-45802 Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST — Apache HTTP ServerCWE-404 5.9 -2023-10-23
CVE-2023-44483 Apache Santuario: Private Key disclosure in debug-log output — Apache SantuarioCWE-532 7.5 -2023-10-20
CVE-2023-46227 Apache inlong has an Arbitrary File Read Vulnerability — Apache InLongCWE-502 9.8 -2023-10-19
CVE-2023-25753 Server-Side Request Forgery in Apache ShenYu — Apache ShenYuCWE-918 9.1 -2023-10-19
CVE-2023-39456 Apache Traffic Server: Malformed http/2 frames can cause an abort — Apache Traffic ServerCWE-20 7.5 -2023-10-17
CVE-2023-41752 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic ServerCWE-200 7.5 -2023-10-17

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.