Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2023-46750 Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro. — Apache ShiroCWE-601 6.1AIMediumAI2023-12-14
CVE-2023-45725 Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design Documents — Apache CouchDBCWE-200 7.5AIHighAI2023-12-13
CVE-2023-50164 Apache Struts: File upload component had a directory traversal vulnerability — Apache StrutsCWE-552 9.8 -2023-12-07
CVE-2023-41835 Apache Struts: excessive disk usage — Apache StrutsCWE-459 8.2 -2023-12-05
CVE-2023-49070 Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present — Apache OFBizCWE-94 9.8 -2023-12-05
CVE-2023-49735 Apache Tiles: Unvalidated input may lead to path traversal and XXE — Apache TilesCWE-22 10.0 -2023-11-30
CVE-2023-49733 Apache Cocoon's StreamGenerator is vulnerable to XXE injection — Apache CocoonCWE-611 7.5 -2023-11-30
CVE-2023-49620 Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for — Apache DolphinSchedulerCWE-862 4.3 -2023-11-30
CVE-2022-45135 Apache Cocoon: SQL injection in DatabaseCookieAuthenticatorAction — Apache CocoonCWE-89 9.8 -2023-11-30
CVE-2023-42504 Apache Superset: Lack of rate limiting allows for possible denial of service — Apache SupersetCWE-770 5.8 Medium2023-11-28
CVE-2023-42505 Apache Superset: Sensitive information disclosure on db connection details — Apache SupersetCWE-200 4.3 Medium2023-11-28
CVE-2023-42502 Apache Superset: Open Redirect Vulnerability — Apache SupersetCWE-601 4.8 Medium2023-11-28
CVE-2023-46589 Apache Tomcat: HTTP request smuggling via malformed trailer headers — Apache TomcatCWE-444 7.5 -2023-11-28
CVE-2022-41678 Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE — Apache ActiveMQCWE-287 8.8 -2023-11-28
CVE-2023-49145 Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt — Apache NiFiCWE-79 7.9 High2023-11-27
CVE-2023-43701 Apache Superset: Stored XSS on API endpoint — Apache SupersetCWE-79 4.3 Medium2023-11-27
CVE-2023-42501 Apache Superset: Unnecessary read permissions within the Gamma role — Apache SupersetCWE-276 4.3 Medium2023-11-27
CVE-2023-40610 Apache Superset: Privilege escalation with default examples database — Apache SupersetCWE-863 6.3 Medium2023-11-27
CVE-2023-49068 Apache DolphinScheduler: Information Leakage Vulnerability — Apache DolphinSchedulerCWE-200 7.5 -2023-11-27
CVE-2023-48796 Apache dolphinscheduler sensitive information disclosure — Apache DolphinSchedulerCWE-200 7.5 -2023-11-24
CVE-2023-43123 Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files — Apache StormCWE-200 5.5 -2023-11-23
CVE-2023-37924 Apache Submarine: SQL injection from unauthorized login — Apache SubmarineCWE-89 8.8AIHighAI2023-11-22
CVE-2022-46337 Apache Derby: LDAP injection vulnerability in authenticator — Apache Derby 9.8AICriticalAI2023-11-20
CVE-2023-46302 Apache Submarine: Fix CVE-2022-1471 SnakeYaml unsafe deserialization — Apache SubmarineCWE-502 9.8AICriticalAI2023-11-20
CVE-2023-26031 Privilege escalation in Apache Hadoop Yarn container-executor binary on Linux systems — Apache HadoopCWE-426 7.8 -2023-11-16
CVE-2023-42781 Apache Airflow: Permission verification bypass allows viewing dagruns of other dags — Apache AirflowCWE-200 4.3 -2023-11-12
CVE-2023-47037 Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access) — Apache AirflowCWE-863 5.4 -2023-11-12
CVE-2023-47248 PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file — PyArrowCWE-502 9.8 -2023-11-09
CVE-2023-39913 Apache UIMA Java SDK Core, Apache UIMA Java SDK CPE, Apache UIMA Java SDK Vinci adapter, Apache UIMA Java SDK tools: Potential untrusted code execution when deserializing certain binary CAS formats — Apache UIMA Java SDK CoreCWE-502 9.8 -2023-11-08
CVE-2023-46819 Apache OFBiz: Execution of Solr plugin queries without authentication — Apache OFBizCWE-306 9.8 -2023-11-07

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.