Skip to content

Apache Software Foundation security advisories

103 advisories · 68 critical or high in 12 months · latest Sep 30

60 of 103 advisories

Advisory
Apache WSS4J: integer overflow
High7.5Sep 30
Apache WSS4J: insufficient authenticity check
Critical9.1Sep 30
Apache WSS4J: protection mechanism failure
High7.5Sep 30
Apache WSS4J: authentication bypass by spoofing
Medium4.8Sep 30
Apache WSS4J: expression injection
Critical9.1Sep 30
Apache WSS4J: authentication bypass
Critical9.8Sep 30
Apache WSS4J: resource exhaustion
High7.5Sep 30
Apache MINA SSHD: resource exhaustion
Medium6.5Sep 30
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache...
Critical9.1Sep 30
Apache MINA SSHD: authentication bypass
Critical9.1Sep 30
Apache MINA SSHD: authentication bypass
Critical9.1Sep 30
Apache MINA SSHD: authentication bypass
High8.1Sep 30
Apache MINA SSHD: improper input validation
Medium6.5Sep 30
Apache MINA SSHD: resource exhaustion
Medium6.5Sep 30
Apache MINA SSHD: resource exhaustion
High7.5Sep 30
Apache PLC4X: denial of service
High8.7Sep 30
Apache PLC4X: integer overflow
High8.7Sep 30
Apache PLC4X: improper array index validation
High8.5Sep 30
Apache PLC4X: improper certificate validation
Critical9.2Sep 30
Apache Polaris: missing authorization
High8.1Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: missing authorization
Medium6.5Sep 29
Apache DolphinScheduler: authentication bypass
Medium5.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: command injection
High8.8Sep 29
Apache DolphinScheduler: missing authentication
Medium6.5Sep 29
Apache XMLSchema: denial of service
High7.5Sep 29
Apache XMLSchema: denial of service
High7.5Sep 29
Apache XMLSchema: denial of service
High7.5Sep 29
Apache Airflow Teradata provider: secrets in logs
Medium6.5Sep 29
Apache Airflow's Google provider built Google Drive search expressions by...
Medium4.3Sep 29
Apache Airflow Snowflake provider: weakly protected credentials
Medium6.3Sep 29
Apache Airflow Teradata provider: SQL injection
Medium6.3Sep 29
Apache Karaf: code execution
Critical9.8Sep 29
Apache Karaf: missing authorization
Medium6.3Sep 29
Apache Karaf: improper access control
High8.8Sep 29
Apache Karaf: path traversal
Critical9.8Sep 29
Apache Karaf: command injection
High8.8Sep 28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and...
High7.3Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: missing authentication
High8.2Sep 28
Apache Roller: unsafe deserialization
Critical9.8Sep 28
Apache Roller: information disclosure
Medium6.5Sep 28
Apache Roller: XML external entity
High7.7Sep 28
Apache Roller: cross-site scripting
Medium5.4Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: server-side request forgery
High7.4Sep 28
Apache Roller: XML external entity
High7.7Sep 28
Apache Roller: missing authorization
Critical9.9Sep 28
Apache Roller: improper authorization
Critical9.0Sep 28
Apache Roller: authentication bypass
High7.7Sep 28
Apache Roller: cross-site request forgery
High8.1Sep 28
Apache Roller: cross-site scripting
Medium5.4Sep 28
Apache Roller: insecure direct object reference
High7.7Sep 28
Apache Qpid Broker-J: denial of service
High7.5Sep 25
Improper Check for Certificate Revocation vulnerability in Apache Tomcat
Medium6.5Sep 23
About Apache Software Foundation

Security advisories Apache Software Foundation publishes for its own products.

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.