Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Apache Software Foundation — Vulnerabilities & Security Advisories 1725

Browse all 1725 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2021-43980 Apache Tomcat: Information disclosure — Apache TomcatCWE-362 3.7 -2022-09-28
CVE-2022-33683 Disabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack — Apache PulsarCWE-295 5.9 -2022-09-23
CVE-2022-33682 Disabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack — Apache PulsarCWE-295 5.9 -2022-09-23
CVE-2022-33681 Improper Hostname Verification in Java Client and Proxy can expose authentication data via MITM — Apache PulsarCWE-295 5.9 -2022-09-23
CVE-2022-24280 Apache Pulsar Proxy target broker address isn't validated — Apache PulsarCWE-20 7.5 -2022-09-23
CVE-2022-26112 Pinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support — Apache Pinot 9.8 -2022-09-23
CVE-2022-40705 Apache SOAP: XML External Entity Injection (XXE) allows unauthenticated users to read arbitrary files via HTTP — Apache SOAPCWE-611 7.5 -2022-09-22
CVE-2022-38398 Server-Side Request Forgery Information Disclosure Vulnerability — Apache XML GraphicsCWE-918 7.5 -2022-09-22
CVE-2022-38648 PDFTranscoder does not block external resources — Apache XML GraphicsCWE-918 5.3 -2022-09-22
CVE-2022-40146 Jar url should be blocked by DefaultScriptSecurity — Apache XML GraphicsCWE-918 7.5 -2022-09-22
CVE-2022-40754 Open Redirect — Apache AirflowCWE-601 6.1 -2022-09-21
CVE-2022-40604 Format String Vulnerability — Apache AirflowCWE-134 7.5 -2022-09-21
CVE-2022-40955 Deserialization attack in Apache InLong prior to version 1.3.0 allows RCE via JDBC — Apache InLongCWE-502 8.8 -2022-09-20
CVE-2022-34917 Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers — Apache KafkaCWE-789 7.5 -2022-09-20
CVE-2022-39135 Apache Calcite: potential XEE attacks — Apache CalciteCWE-611 9.8 -2022-09-11
CVE-2022-28220 STARTTLS command injection in Apache JAMES — Apache JamesCWE-77 7.5 -2022-09-08
CVE-2022-38370 No authorization of DatabaseConnectController in grafana-connector. — Apache IoTDB 5.3 -2022-09-05
CVE-2022-38369 Login check vulnerability by session Id — Apache IoTDB 8.1 -2022-09-05
CVE-2022-38054 Session Fixation — Apache AirflowCWE-384 9.8 -2022-09-02
CVE-2022-38170 Overly permissive umask for daemons — Apache Airflow 4.7 -2022-09-02
CVE-2022-29158 Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz — Apache OFBizCWE-1333 7.5 -2022-09-02
CVE-2022-29063 Java Deserialization via RMI Connection from the Solr plugin of Apache OFBiz — Apache OFBizCWE-502 9.8 -2022-09-02
CVE-2022-25813 Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz — Apache OFBizCWE-1336 7.5 -2022-09-02
CVE-2022-25371 Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz — Apache OFBizCWE-22 9.8 -2022-09-02
CVE-2022-25370 Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz — Apache OFBizCWE-79 5.4 -2022-09-02
CVE-2022-37435 Apache ShenYu Admin Improper Privilege Management — Apache ShenYuCWE-732 8.8 -2022-09-01
CVE-2022-37023 Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11 — Apache GeodeCWE-502 8.8 -2022-08-31
CVE-2022-37022 Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 11 — Apache GeodeCWE-502 9.8 -2022-08-31
CVE-2022-37021 Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8. — Apache GeodeCWE-502 9.8 -2022-08-31
CVE-2021-25642 Apache Hadoop YARN remote code execution in ZKConfigurationStore of capacity scheduler — Apache HadoopCWE-502 8.8 -2022-08-25

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.