Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2018-11774

    Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires ... Read more

    Affected Products : virtual_computing_lab
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11773

    Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implem... Read more

    Affected Products : virtual_computing_lab
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-11772

    Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access ... Read more

    Affected Products : virtual_computing_lab
    • Published: Jul. 29, 2019
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-11771

    When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStre... Read more

    • Published: Aug. 16, 2018
    • Modified: Nov. 21, 2024
  • 4.9

    MEDIUM
    CVE-2018-11770

    From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for... Read more

    Affected Products : spark
    • Published: Aug. 13, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-11769

    CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their pr... Read more

    Affected Products : couchdb
    • Published: Aug. 08, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11768

    In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage.... Read more

    Affected Products : hadoop
    • Published: Oct. 04, 2019
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2018-11767

    In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.... Read more

    Affected Products : hadoop
    • Published: Mar. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-11766

    In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.... Read more

    Affected Products : hadoop
    • Published: Nov. 27, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11765

    In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.... Read more

    Affected Products : hadoop
    • Published: Sep. 30, 2020
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-11764

    Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.... Read more

    Affected Products : hadoop
    • Published: Oct. 21, 2020
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2018-11763

    In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation ... Read more

    • Published: Sep. 25, 2018
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2018-11762

    In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file... Read more

    Affected Products : tika
    • Published: Sep. 19, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11761

    In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.... Read more

    • Published: Sep. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-11760

    When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1.... Read more

    Affected Products : spark
    • Published: Feb. 04, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11759

    The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supporte... Read more

    • Published: Oct. 31, 2018
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2018-11758

    This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shipped with Apache Cayenne and intended for editing Cayenne ORM models stored as XML files. If an attacker tric... Read more

    Affected Products : cayenne
    • Published: Aug. 22, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11757

    In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an attacker to replace the user function inside the container if the user code is vulnerable to code exploitat... Read more

    Affected Products : openwhisk
    • Published: Jul. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11756

    In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1.0.1 (or earlier) may allow an attacker to replace the user function inside the container if the user code... Read more

    Affected Products : php openwhisk
    • Published: Jul. 23, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-11752

    Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 release.... Read more

    Affected Products : cisco_ios
    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 294121 Results