Safeguard
Tag

apache

Safeguard articles tagged "apache" — guides, analysis, and best practices for software supply chain and application security.

44 articles

Vulnerability Analysis

CVE-2022-24706: Apache CouchDB Insecure Default Initialization of Resource Vulnerability

CVE-2022-24706 affects Apache CouchDB and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-08-25.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2022-33891: Apache Spark Command Injection Vulnerability

CVE-2022-33891 affects Apache Spark and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-03-07.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2021-45046: Apache Log4j2 Deserialization of Untrusted Data Vulnerability

CVE-2021-45046 affects Apache Log4j2 and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-05-01.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2016-8735: Apache Tomcat Remote Code Execution Vulnerability

CVE-2016-8735 affects Apache Tomcat and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-05-12.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2023-33246: Apache RocketMQ Command Execution Vulnerability

CVE-2023-33246 affects Apache RocketMQ and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-09-06.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2023-46604: Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

CVE-2023-46604 affects Apache ActiveMQ and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-11-02.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2023-27524: Apache Superset Insecure Default Initialization of Resource Vulnerability

CVE-2023-27524 affects Apache Superset and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-08.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2020-17519: Apache Flink Improper Access Control Vulnerability

CVE-2020-17519 affects Apache Flink and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-05-23.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-32113: Apache OFBiz Path Traversal Vulnerability

CVE-2024-32113 affects Apache OFBiz and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-08-07.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerability

CVE-2024-38856 affects Apache OFBiz and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-08-27.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-27348: Apache HugeGraph-Server Improper Access Control Vulnerability

CVE-2024-27348 affects Apache HugeGraph-Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-09-18.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-45195: Apache OFBiz Forced Browsing Vulnerability

CVE-2024-45195 affects Apache OFBiz and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-02-04.

Sep 17, 20263 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.