apache security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect apache products.
Vulnios monitors apache CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent apache security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2021-23901 — apache, netapp — nutch, snap_creator_framework
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web sec
criticalCVE-2021-23901Critical Vulnerability: CVE-2021-23926 — apache, netapp — xmlbeans, oncommand_unified_manager_core_package
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion atta
criticalCVE-2021-23926Critical Vulnerability: CVE-2020-11995 — apache — dubbo
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserializatio
criticalCVE-2020-11995Critical Vulnerability: CVE-2020-13931 — apache — tomee
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP
criticalCVE-2020-13931Critical Vulnerability: CVE-2020-11974 — apache — dolphinscheduler
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
criticalCVE-2020-11974Critical Vulnerability: CVE-2020-17528 — apache — nuttx
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer o
criticalCVE-2020-17528Critical Vulnerability: CVE-2020-17529 — apache — nuttx
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offse
criticalCVE-2020-17529Critical Vulnerability: CVE-2020-17531 — apache — tapestry
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserial
criticalCVE-2020-17531Critical Vulnerability: CVE-2020-13942 — apache — unomi
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scrip
criticalCVE-2020-13942Critical Vulnerability: CVE-2020-17510 — apache, debian — shiro, debian_linux
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
criticalCVE-2020-17510Critical Vulnerability: CVE-2020-13957 — apache — solr
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that'
criticalCVE-2020-13957Critical Vulnerability: CVE-2019-0230 — apache, oracle — struts, communications_policy_management
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
criticalCVE-2019-0230Critical Vulnerability: CVE-2020-11998 — apache, oracle — activemq, communications_diameter_signaling_router
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it le
criticalCVE-2020-11998Critical Vulnerability: CVE-2020-11986 — apache — netbeans
To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project.
criticalCVE-2020-11986Critical Vulnerability: CVE-2020-11984 — apache, netapp — http_server, clustered_data_ontap
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
criticalCVE-2020-11984Critical Vulnerability: CVE-2020-13921 — apache — skywalking
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
criticalCVE-2020-13921Critical Vulnerability: CVE-2020-11981 — apache — airflow
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resu
criticalCVE-2020-11981Critical Vulnerability: CVE-2020-11982 — apache — airflow
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious pay
criticalCVE-2020-11982Critical Vulnerability: CVE-2020-13925 — apache — kylin
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validati
criticalCVE-2020-13925Critical Vulnerability: CVE-2020-1948 — apache — dubbo
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloa
criticalCVE-2020-1948Critical Vulnerability: CVE-2020-13926 — apache — kylin
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain
criticalCVE-2020-13926Critical Vulnerability: CVE-2020-9480 — apache, oracle — spark, business_intelligence
In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-craft
criticalCVE-2020-9480Critical Vulnerability: CVE-2020-11989 — apache — shiro
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
criticalCVE-2020-11989Critical Vulnerability: CVE-2020-11969 — apache — tomee
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication.
criticalCVE-2020-11969Critical Vulnerability: CVE-2020-11975 — apache — unomi
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process
criticalCVE-2020-11975Critical Vulnerability: CVE-2020-1963 — apache — ignite
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
criticalCVE-2020-1963Critical Vulnerability: CVE-2019-17562 — apache — cloudstack
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the
criticalCVE-2019-17562Critical Vulnerability: CVE-2020-11973 — apache, oracle — camel, communications_diameter_signaling_router
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to
criticalCVE-2020-11973Critical Vulnerability: CVE-2020-11972 — apache, oracle — camel, communications_diameter_signaling_router
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade
criticalCVE-2020-11972Critical Vulnerability: CVE-2020-1955 — apache — couchdb
CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the
criticalCVE-2020-1955Critical Vulnerability: CVE-2020-1939 — apache — nuttx
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereferenc
criticalCVE-2020-1939Critical Vulnerability: CVE-2018-1285 — apache, fedoraproject — log4net, fedora
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled l
criticalCVE-2018-1285Critical Vulnerability: CVE-2020-1959 — apache — syncope
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) v
criticalCVE-2020-1959Critical Vulnerability: CVE-2020-1961 — apache — syncope
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressi
criticalCVE-2020-1961Critical Vulnerability: CVE-2020-1952 — apache — iotdb
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
criticalCVE-2020-1952Critical Vulnerability: CVE-2020-1964 — apache — heron
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resul
criticalCVE-2020-1964Critical Vulnerability: CVE-2019-17564 — apache — dubbo
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of
criticalCVE-2019-17564Critical Vulnerability: CVE-2019-17560 — apache, oracle — netbeans, graalvm
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the downloa
criticalCVE-2019-17560Critical Vulnerability: CVE-2020-1957 — apache, debian — shiro, debian_linux
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
criticalCVE-2020-1957Critical Vulnerability: CVE-2019-17565 — apache, debian — traffic_server, debian_linux
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions
criticalCVE-2019-17565Critical Vulnerability: CVE-2020-1944 — apache, debian — traffic_server, debian_linux
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9
criticalCVE-2020-1944Critical Vulnerability: CVE-2019-17559 — apache, debian — traffic_server, debian_linux
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
criticalCVE-2019-17559Critical Vulnerability: CVE-2020-1953 — apache, oracle — commons_configuration, database_server
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration v
criticalCVE-2020-1953Critical Vulnerability: CVE-2020-1947 — apache — shardingsphere
In Apache ShardingSphere(incubator) 4.0.0-RC3 and 4.0.0, the ShardingSphere's web console uses the SnakeYAML library for parsing YAML inputs to load datasource configuration. SnakeYAML allows to unmar
criticalCVE-2020-1947Critical Vulnerability: CVE-2019-17570 — apache, debian — xml-rpc, debian_linux
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RP
criticalCVE-2019-17570Critical Vulnerability: CVE-2019-0219 — apache, oracle — cordova_inappbrowser, instantis_enterprisetrack
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
criticalCVE-2019-0219Critical Vulnerability: CVE-2020-5499 — apache — rust_sgx_sdk
Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.
criticalCVE-2020-5499Critical Vulnerability: CVE-2019-17571 — apache, debian — log4j, debian_linux
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gad
criticalCVE-2019-17571Critical Vulnerability: CVE-2019-17556 — apache — olingo
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious met
criticalCVE-2019-17556Critical Vulnerability: CVE-2019-12409 — apache, linux — solr, linux_kernel
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use
criticalCVE-2019-12409Critical Vulnerability: CVE-2019-12419 — apache, oracle — cxf, commerce_guided_search
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it doe
criticalCVE-2019-12419Critical Vulnerability: CVE-2019-10082 — apache, oracle — http_server, communications_element_manager
In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
criticalCVE-2019-10082Critical Vulnerability: CVE-2019-0195 — apache — tapestry
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-pas
criticalCVE-2019-0195Critical Vulnerability: CVE-2019-10071 — apache — tapestry
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code ex
criticalCVE-2019-10071Critical Vulnerability: CVE-2018-17200 — apache — ofbiz
The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent
criticalCVE-2018-17200Critical Vulnerability: CVE-2019-0189 — apache — ofbiz
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution
criticalCVE-2019-0189Critical Vulnerability: CVE-2019-10074 — apache — ofbiz
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input
criticalCVE-2019-10074Critical Vulnerability: CVE-2019-12405 — apache — traffic_control
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authentica
criticalCVE-2019-12405Critical Vulnerability: CVE-2018-11773 — apache — virtual_computing_lab
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime.
criticalCVE-2018-11773Critical Vulnerability: CVE-2018-11779 — apache — storm
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Jav
criticalCVE-2018-11779
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track apache exposure across your environment
Vulnios automatically cross-references your asset inventory against new apache CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan