PatchSiren

Apache CVE debriefs · Page 6

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Apache CVE published 2024-08-07

CVE-2024-32113

CVE-2024-32113 is a path traversal vulnerability affecting Apache OFBiz. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2024-08-07, which means defenders should treat it as a high-priority issue and act by the 2024-08-28 due date.

Known exploited Apache CVE published 2024-05-23

CVE-2020-17519

CVE-2020-17519 is an Apache Flink improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-05-23. The CISA entry directs defenders to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Because the supplied corpus does not include affected versions, fixed releases, or a CVSS score, this debrief focuses on defensive [truncated]

Known exploited Apache CVE published 2024-01-08

CVE-2023-27524

CVE-2023-27524 is an Apache Superset vulnerability described as an insecure default initialization of a resource. The supplied official record is sparse on exploit mechanics and impact, but CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-08, which makes it a high-priority defensive issue. Treat any exposed Superset deployment as needing prompt validation, mitigation, or upgrade.

Known exploited Apache CVE published 2023-11-02

CVE-2023-46604

CVE-2023-46604 is a deserialization of untrusted data vulnerability in Apache ActiveMQ. CISA has placed it in the Known Exploited Vulnerabilities catalog and marked it as known ransomware campaign use, which makes this a high-priority issue for defenders. CISA’s required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Known exploited Apache CVE published 2023-09-06

CVE-2023-33246

CVE-2023-33246 is an Apache RocketMQ command execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-09-06. Because it is listed in KEV, defenders should treat it as an active risk and prioritize mitigation using vendor guidance or remove/discontinue use if mitigation is not available.

Known exploited Apache CVE published 2023-05-12

CVE-2016-8735

CVE-2016-8735 is recorded in the supplied corpus as an Apache Tomcat remote code execution vulnerability and is also listed in CISA’s Known Exploited Vulnerabilities catalog. For defenders, the practical takeaway is straightforward: treat it as a patch-now issue and follow vendor update guidance. The supplied source data does not provide a CVSS score, so prioritization here is driven by KEV status and the [truncated]

Known exploited Apache CVE published 2023-05-01

CVE-2021-45046

CVE-2021-45046 is a publicly listed Apache Log4j2 vulnerability described as deserialization of untrusted data. In the supplied CISA Known Exploited Vulnerabilities record, it is marked as known exploited and associated with known ransomware campaign use. CISA added it to the KEV catalog on 2023-05-01 and set a remediation due date of 2023-05-22, with the required action to apply updates per vendor instructions.

Known exploited Apache CVE published 2023-03-07

CVE-2022-33891

CVE-2022-33891 is a command injection vulnerability in Apache Spark that CISA added to its Known Exploited Vulnerabilities catalog on 2023-03-07. Because it is listed in KEV, defenders should treat it as actively exploited risk and prioritize remediation using vendor guidance.

Known exploited Apache CVE published 2022-08-25

CVE-2022-24706

CVE-2022-24706 is a publicly disclosed Apache CouchDB vulnerability described as an insecure default initialization of a resource. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25, which makes timely remediation a high priority for any organization running CouchDB.

Known exploited Apache CVE published 2022-08-25

CVE-2022-24112

CVE-2022-24112 is an Apache APISIX authentication bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on the same day it was published. Because it is in the KEV list, defenders should treat it as a high-priority issue and follow vendor update guidance promptly.

Known exploited Apache CVE published 2022-03-25

CVE-2020-1956

CVE-2020-1956 is an Apache Kylin operating-system command injection vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, organizations using Apache Kylin should treat it as a high-priority remediation item and apply vendor updates per Apache instructions.

Known exploited Apache CVE published 2022-03-25

CVE-2017-12617

CVE-2017-12617 is an Apache Tomcat remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That designation means defenders should treat it as actively exploited and prioritize remediation using vendor guidance. The supplied CISA metadata specifies the required action as applying updates per vendor instructions, with a KEV due date of 2022-04-15.

Known exploited Apache CVE published 2022-03-25

CVE-2017-12615

CVE-2017-12615 is an Apache Tomcat vulnerability affecting Windows deployments that CISA lists in its Known Exploited Vulnerabilities catalog as actively exploited. CISA also marks it as associated with known ransomware campaign use. From a defensive standpoint, this is a high-priority patching and exposure review item for any organization running Tomcat on Windows.

Known exploited Apache CVE published 2022-03-25

CVE-2013-2251

CVE-2013-2251 is an Apache Struts improper input validation vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV status means the issue has been observed in exploitation and should be treated as a high-priority patching item. CISA’s required action is to apply updates per vendor instructions.

Known exploited Apache CVE published 2022-03-03

CVE-2020-1938

CVE-2020-1938 is an Apache Tomcat vulnerability described as an improper privilege management issue and listed by CISA in the Known Exploited Vulnerabilities catalog. Because CISA has added it to KEV, defenders should treat it as a high-priority remediation item and apply vendor-directed updates without delay.

Known exploited Apache CVE published 2022-02-10

CVE-2017-9791

CVE-2017-9791 is an Apache Struts 1 improper input validation vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, so defenders should treat affected systems as a priority for remediation. The supplied sources do not include a CVSS score, so operational urgency should be driven by the KEV listing and vendor guidance.

Known exploited Apache CVE published 2022-02-10

CVE-2016-3088

CVE-2016-3088 is an Apache ActiveMQ issue described as improper input validation and included in CISA’s Known Exploited Vulnerabilities catalog. Because CISA has marked it as a known exploited vulnerability, organizations running ActiveMQ should treat it as a high-priority patching item and follow vendor update guidance without delay.

Known exploited Apache CVE published 2022-01-21

CVE-2012-0391

CVE-2012-0391 is an Apache Struts 2 improper input validation vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. In the provided CISA record, the vulnerability was added on 2022-01-21 and assigned a remediation due date of 2022-07-21, with the required action to apply updates per vendor instructions. Because it is KEV-listed, organizations using Apache Struts 2 should tre [truncated]

Known exploited Apache CVE published 2022-01-21

CVE-2006-1547

CVE-2006-1547 is a denial-of-service vulnerability associated with Apache Struts 1 ActionForm. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it has been identified as actively exploited in the wild. Organizations still running Struts 1 should treat this as a high-priority legacy application risk and follow vendor update guidance immediately.

Known exploited Apache CVE published 2022-01-18

CVE-2020-13927

CVE-2020-13927 affects Apache Airflow’s Experimental API and is identified by CISA as a known exploited vulnerability. The issue is described as an authentication bypass, which means an attacker could potentially access the API without proper authentication. Because it is listed in the KEV catalog, defenders should treat it as a priority remediation item and apply vendor-recommended updates as soon as possible.

Known exploited Apache CVE published 2022-01-18

CVE-2020-11978

CVE-2020-11978 is a command injection vulnerability in Apache Airflow that CISA has placed in the Known Exploited Vulnerabilities catalog. That combination makes it a high-priority issue for any organization running Airflow, because it indicates a vulnerability with real-world exploitation concern and a clear need to remediate quickly.

Known exploited Apache CVE published 2021-12-10

CVE-2021-44228

CVE-2021-44228 is a high-priority Apache Log4j2 remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-12-10. CISA also marks it as associated with known ransomware campaign use. For affected assets where updates exist, CISA’s required remediation is to apply updates or remove the affected assets from agency networks; temporary mitigations are only accep [truncated]

Known exploited Apache CVE published 2021-12-10

CVE-2019-0193

CVE-2019-0193 is a code injection vulnerability affecting Apache Solr DataImportHandler. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a priority for remediation. Based on the supplied timeline, the KEV record was added on 2021-12-10 and the required action was to apply updates per vendor instructions.

Known exploited Apache CVE published 2021-12-01

CVE-2021-40438

CVE-2021-40438 is an Apache HTTP Server server-side request forgery (SSRF) issue that CISA added to its Known Exploited Vulnerabilities catalog on 2021-12-01. Because it is listed in KEV, organizations should treat remediation as urgent and follow the vendor’s update guidance promptly.

Known exploited Apache CVE published 2021-11-03

CVE-2021-42013

CVE-2021-42013 is a path traversal vulnerability in Apache HTTP Server that was added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-03. CISA lists it as known to be exploited and associated with known ransomware campaign use, so exposed Apache HTTP Server deployments should be treated as a high-priority remediation item.

Known exploited Apache CVE published 2021-11-03

CVE-2021-41773

CVE-2021-41773 is a path traversal vulnerability affecting Apache HTTP Server. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and marked it as known to be used in ransomware campaigns. For defenders, this is an urgent patching and verification item for any Apache HTTP Server deployment, especially exposed internet-facing instances.

Known exploited Apache CVE published 2021-11-03

CVE-2020-17530

CVE-2020-17530 is an Apache Struts remote code execution vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog on 2021-11-03. The supplied corpus indicates active known exploitation, so organizations running Struts should treat this as a patch-priority issue and follow vendor update guidance promptly.

Known exploited Apache CVE published 2021-11-03

CVE-2019-17558

CVE-2019-17558 is a remote code execution vulnerability in Apache Solr’s VelocityResponseWriter plug-in. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which indicates it has been observed as actively exploited and should be treated as a high-priority remediation item.

Known exploited Apache CVE published 2021-11-03

CVE-2019-0211

CVE-2019-0211 is identified in the supplied corpus as an Apache HTTP Server privilege escalation vulnerability and is listed by CISA in the Known Exploited Vulnerabilities (KEV) catalog. The safest response is to treat this as a high-priority patching item and apply Apache’s vendor updates as soon as possible. The source material provided here does not include exploit mechanics, affected versions, or work [truncated]

Known exploited Apache CVE published 2021-11-03

CVE-2018-11776

CVE-2018-11776 is an Apache Struts remote code execution vulnerability that CISA has listed in the Known Exploited Vulnerabilities catalog. Because it is tracked as known exploited, organizations using Apache Struts should prioritize remediation over routine maintenance and apply vendor-recommended updates as soon as possible. CISA’s KEV entry cites applying updates per vendor instructions, with the issue [truncated]