Apache Tomcat versions up to 11.0.25, 10.1.59, and 9.0.121 let users bypass security checks on WebSocket connections, potentially letting anyone…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachetomcat #apachefoundation #Debian13 #CVE #infosec
Apache Tomcat versions up to 11.0.25, 10.1.59, and 9.0.121 let users bypass security checks on WebSocket connections, potentially letting anyone…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachetomcat #apachefoundation #Debian13 #CVE #infosec
Versions of Apache Tomcat 9.0.118‑9.0.121, 10.1.55‑10.1.59, and 11.0.22‑11.0.25 can misinterpret incoming HTTP/2 traffic, causing request headers to…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachetomcat #apachefoundation #Debian13 #CVE #infosec
Versions of Apache Tomcat 9.0.118‑9.0.121, 10.1.55‑10.1.59, and 11.0.22‑11.0.25 can misinterpret incoming HTTP/2 traffic, causing request headers to…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachetomcat #apachefoundation #Debian13 #CVE #infosec
Certain versions of Apache Tomcat (11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121) can incorrectly allow client certificate…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachetomcat #apachefoundation #Debian13 #CVE #infosec
Certain versions of Apache Tomcat (11.0.0-M14 to 11.0.25, 10.1.22 to 10.1.59, and 9.0.92 to 9.0.121) can incorrectly allow client certificate…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachetomcat #apachefoundation #Debian13 #CVE #infosec
When a user logs into the management interface of Apache Qpid Broker-J, the system keeps the same session identifier instead of creating a new one. This allows a remote…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
When a user logs into the management interface of Apache Qpid Broker-J, the system keeps the same session identifier instead of creating a new one. This allows a remote…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
The tar handling part of Apache BuildStream may follow symbolic links inside a malicious source archive and create or overwrite files on the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachebuildstream #apachefoundation #Debian12 #CVE #infosec
The tar handling part of Apache BuildStream may follow symbolic links inside a malicious source archive and create or overwrite files on the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachebuildstream #apachefoundation #Debian12 #CVE #infosec
When users sign out of Apache Airflow using a bearer token in the Authorization header, the system only clears the browser cookie and leaves the token active…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheairflow #apachefoundation #CVE #infosec
When users sign out of Apache Airflow using a bearer token in the Authorization header, the system only clears the browser cookie and leaves the token active…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheairflow #apachefoundation #CVE #infosec
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects. This means an…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachemina #apachefoundation #CVE #infosec
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects. This means an…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachemina #apachefoundation #CVE #infosec
If an attacker can see traffic on the same network, they can trick Artemis into sending its cluster administrator credentials during the initial connection…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheartemis #apachefoundation #CVE #infosec
If an attacker can see traffic on the same network, they can trick Artemis into sending its cluster administrator credentials during the initial connection…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheartemis #apachefoundation #CVE #infosec
Apache Ranger's lookup feature can be exploited to inject malicious SQL code. This can lead to unauthorized data access or modification. To fix this issue,…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheranger #apachefoundation #CVE #infosec
Apache Ranger's lookup feature can be exploited to inject malicious SQL code. This can lead to unauthorized data access or modification. To fix this issue,…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheranger #apachefoundation #CVE #infosec
OpenNLP’s built‑in email and web‑address detectors can be tricked by specially crafted text, causing the program to use excessive CPU time or run out of memory…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheopennlp #apachefoundation #CVE #infosec
OpenNLP’s built‑in email and web‑address detectors can be tricked by specially crafted text, causing the program to use excessive CPU time or run out of memory…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apacheopennlp #apachefoundation #CVE #infosec
Certain versions of Apache MyFaces can be told to access internal network locations or read files on the server, which could expose sensitive information. This…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachemyfaces #apachefoundation #CVE #infosec
Certain versions of Apache MyFaces can be told to access internal network locations or read files on the server, which could expose sensitive information. This…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachemyfaces #apachefoundation #CVE #infosec
If your Airflow installation uses the Keycloak authentication manager and shares the Keycloak realm with other applications, any of those applications can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
If your Airflow installation uses the Keycloak authentication manager and shares the Keycloak realm with other applications, any of those applications can…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
Apache Gravitino's MCP REST client fails to properly encode user input in URLs, potentially allowing attackers to access sensitive data or API endpoints.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachegravitino #apachefoundation #CVE #infosec
Apache Gravitino's MCP REST client fails to properly encode user input in URLs, potentially allowing attackers to access sensitive data or API endpoints.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachegravitino #apachefoundation #CVE #infosec
When a password is changed in Airflow using the FAB authentication manager with database‑backed sessions, existing user sessions are not removed because the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
When a password is changed in Airflow using the FAB authentication manager with database‑backed sessions, existing user sessions are not removed because the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
When a password is changed through the admin interface in Apache Airflow's FAB provider, any existing login sessions that use the database for session storage…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
When a password is changed through the admin interface in Apache Airflow's FAB provider, any existing login sessions that use the database for session storage…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
If you run Apache Airflow version 3.3 or newer with the Keycloak authentication add‑on, a user’s login session can be combined with a different person’s…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
If you run Apache Airflow version 3.3 or newer with the Keycloak authentication add‑on, a user’s login session can be combined with a different person’s…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
If the Storm configuration defines only group restrictions (nimbus.groups) and leaves the user list (nimbus.users) empty, the system does not enforce those group rules.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
If the Storm configuration defines only group restrictions (nimbus.groups) and leaves the user list (nimbus.users) empty, the system does not enforce those group rules.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
In certain versions of Apache Syncope, an admin with proper rights can insert malicious input that makes the system execute any database command. This could let…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
In certain versions of Apache Syncope, an admin with proper rights can insert malicious input that makes the system execute any database command. This could let…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
Apache Syncope versions from 3.0.0‑M0 to 4.1.2 can accept forged authentication tokens when OAuth 2.0 is set up without a proper key source. An attacker could…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
Apache Syncope versions from 3.0.0‑M0 to 4.1.2 can accept forged authentication tokens when OAuth 2.0 is set up without a proper key source. An attacker could…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
Apache Storm worker nodes accept specially crafted network packets before checking who sent them. An attacker who can reach a worker's port could cause the worker to use…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
Apache Storm worker nodes accept specially crafted network packets before checking who sent them. An attacker who can reach a worker's port could cause the worker to use…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
If an administrator with sufficient rights uses the task‑search feature, they can insert specially crafted sorting instructions that cause the system to execute…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
If an administrator with sufficient rights uses the task‑search feature, they can insert specially crafted sorting instructions that cause the system to execute…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
Certain versions of Apache Syncope (3.0.0‑M0 through 3.0.16 and 4.0.0‑M0 through 4.1.2) can expose the settings used to verify internal login tokens. If an…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
Certain versions of Apache Syncope (3.0.0‑M0 through 3.0.16 and 4.0.0‑M0 through 4.1.2) can expose the settings used to verify internal login tokens. If an…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
The DRPC component of Apache Storm stores each request name forever, even if it is never used again. An attacker can send many fake request names and cause the server to…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
The DRPC component of Apache Storm stores each request name forever, even if it is never used again. An attacker can send many fake request names and cause the server to…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachefoundation #CVE #infosec
Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2 can omit permission checks on certain search queries, allowing users to see information they shouldn’t.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
Apache Syncope versions up to 3.0.16, 4.0.7 and 4.1.2 can omit permission checks on certain search queries, allowing users to see information they shouldn’t.…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
In certain versions of Apache Syncope, an administrator who has rights in one area could use the REST interface to see the full configuration of connectors…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec
In certain versions of Apache Syncope, an administrator who has rights in one area could use the REST interface to see the full configuration of connectors…
Too many irrelevant or confusing CVEs? Use stackflag.com
#apachesyncope #apachefoundation #CVE #infosec