Collected every two hours from specialised publications — each link leads to the original article.
Apache Log4j2, a Java Logging Framework, is vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configur…
The Apache Software Foundation (ASF) on Tuesday rolled out fresh patches to contain an arbitrary code execution flaw in Log4j that could be abused by threat ac…
Several security vulnerabilities were found in Apache Log4j2, a Logging Framework for Java, which could lead to a denial of service or information disclosure.
Updated apache packages fix security vulnerabilities: A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL poin…
Updated apache-mod_security packages fix security vulnerability: ModSecurity mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens…
Apache has released another update shortly after the second Log4j update addressing a previously “incomplete…Apache Releases Third Major Log4j Update To Fix A …
The issues with Log4j continued to stack up as the Apache Software Foundation (ASF) on Friday rolled out yet another patch — version 2.17.0 — for the widely us…
Apache Log4j 2 could be made to crash if it received specially crafted input.
After the disastrous Log4j vulnerability disrupted the online world, another vulnerability surfaced online. It turns…Another Apache Log4j Bug Discovered – Patc…
As the critical “Log4Shell” bug stirs up the internet, the cybersecurity community is rushing for…‘Vaccine’ For Apache Log4j Vulnerability Released Amidst Acti…
Chen Zhaojun of Alibaba Cloud Security Team discovered a critical security vulnerability in Apache Log4j, a popular Logging Framework for Java. JNDI features u…
The package apache before version 2.4.51-1 is vulnerable to directory traversal.
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files …
Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition a vulnerability was discovered in mod_p…
Developers behind the Apache HTTP Server Project are urging users to apply a fix immediately to resolve a zero-day vulnerability.
Several vulnerabilities were discovered in the Apache HTTP server. An attacker could send proxied requests to arbitrary servers, corrupt memory in some setups …
Apache Commons IO could be made to expose sensitive information if it received a specially crafted input.
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in Apache HTTP Server.
Apache OpenOffice (AOO) is currently vulnerable to a remote code execution vulnerability (CVE-2021-33035) recently discovered by security researcher Eugene Lim…
Multiple vulnerabilities have been found in Apache Velocity, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Apache Commons FileUpload, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.
Apache Commons Collections unsafely deserializes untrusted input, potentially resulting in arbitrary code execution.