Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2023-29032 Apache OpenMeetings: allows bypass authentication — Apache OpenMeetingsCWE-287 8.8 -2023-05-12
CVE-2023-29246 Apache OpenMeetings: allows null-byte Injection — Apache OpenMeetingsCWE-20 7.2 -2023-05-12
CVE-2023-25754 Apache Airflow: Privilege escalation using airflow logs — Apache AirflowCWE-270 7.5 -2023-05-08
CVE-2023-29247 Stored XSS on Apache Airflow — Apache AirflowCWE-79 6.1 -2023-05-08
CVE-2023-31039 Apache bRPC: ServerOptions.pid_file may cause arbitrary code execution — Apache bRPCCWE-20 9.8 -2023-05-08
CVE-2023-31038 Apache Log4cxx: SQL injection when using ODBC appender — Apache Log4cxxCWE-89 7.2 -2023-05-08
CVE-2021-40331 Permissions problem in the Apache Ranger Hive Plugin — Apache Ranger Hive PluginCWE-732 6.5 -2023-05-05
CVE-2022-45048 Apache Ranger: code execution vulnerability in policy expressions — Apache RangerCWE-74 8.4 High2023-05-05
CVE-2023-26268 Apache CouchDB, IBM Cloudant: Information sharing via couchjs processes — Apache CouchDBCWE-200 4.4 Medium2023-05-02
CVE-2023-32007 Apache Spark: Shell command injection via Spark UI — Apache SparkCWE-77 8.8 -2023-05-02
CVE-2022-46365 Apache StreamPark (incubating): Logic error causing any account reset — Apache StreamPark (incubating)CWE-20 8.1 -2023-05-01
CVE-2022-45801 Apache StreamPark (incubating): LDAP Injection Vulnerability — Apache StreamPark (incubating)CWE-74 9.1 -2023-05-01
CVE-2022-45802 Apache StreamPark (incubating): Upload any file to any directory — Apache StreamPark (incubating)CWE-434 8.1 -2023-05-01
CVE-2023-22665 Apache Jena: Exposure of arbitrary execution in script engine expressions. — Apache JenaCWE-917 6.1 -2023-04-25
CVE-2023-30776 Apache Superset: Database connection password leak — Apache SupersetCWE-522 4.9 Medium2023-04-24
CVE-2023-27524 Apache Superset: Session validation vulnerability when using provided default SECRET_KEY — Apache SupersetCWE-1188 8.9 High2023-04-24
CVE-2023-25601 Apache DolphinScheduler 3.0.0 to 3.1.1 python gateway has improper authentication — Apache DolphinSchedulerCWE-287 9.1 -2023-04-20
CVE-2023-25504 Apache Superset: Possible SSRF on import datasets — Apache SupersetCWE-918 4.9 Medium2023-04-17
CVE-2023-27525 Apache Superset: Incorrect default permissions for Gamma role — Apache SupersetCWE-863 3.1 Low2023-04-17
CVE-2023-22946 Apache Spark proxy-user privilege escalation from malicious configuration class — Apache SparkCWE-269 6.4 Medium2023-04-17
CVE-2023-30771 Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench — Apache IoTDB WorkbenchCWE-863 9.8 -2023-04-17
CVE-2023-24831 Apache IoTDB grafana-connector Login Bypass Vulnerability — Apache IoTDBCWE-287 8.8 -2023-04-17
CVE-2022-47501 Apache OFBiz: Arbitrary file reading vulnerability — Apache OFBizCWE-22 7.5 -2023-04-14
CVE-2022-45064 Apache Sling Engine: Include-based XSS — Apache Sling EngineCWE-79 8.0 High2023-04-13
CVE-2023-30465 Apache InLong: SQL injection in apache inLong 1.5.0 — Apache InLongCWE-89 5.3 -2023-04-11
CVE-2023-29216 Apache Linkis DatasourceManager module has a deserialization command execution — Apache LinkisCWE-502 9.8 -2023-04-10
CVE-2023-27987 Apache Linkis gateway module token authentication bypass — Apache LinkisCWE-326 9.1 -2023-04-10
CVE-2023-27603 Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue — Apache LinkisCWE-22 9.8 -2023-04-10
CVE-2023-27602 Apache Linkis publicsercice module unrestricted upload of file — Apache LinkisCWE-434 9.8 -2023-04-10
CVE-2023-29215 Apache Linkis JDBC EngineCon has a deserialization command execution — Apache LinkisCWE-502 9.8 -2023-04-10

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.