Collected every two hours from specialised publications — each link leads to the original article.
Multiple vulnerabilities have been found in Apache Thrift, the worst of which could result in a Denial of Service condition.
Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes …
Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes …
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in Apache HTTP Server.
On April 12, 2021, the Apache SpamAssassin Project announced the release of Apache SpamAssassin Version 3.4.6 mitigating two small but potentially annoying bug…
The Apache Software Foundation on Friday addressed a high severity vulnerability in Apache OFBiz that could have allowed an unauthenticated adversary to remote…
Apache Tika could be made to crash if it opened a specially crafted file.
Apache XML-RPC could be made to execute arbitrary code if it received specially crafted data by a malicious XML-RPC server.
Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.
If your web-server runs on Apache, you should immediately install the latest available version of the server application to prevent hackers from taking unautho…
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the serv…
Several security issues were fixed in Apache HTTP Server.
A new research has uncovered multiple critical reverse RDP vulnerabilities in Apache Guacamole, a popular remote desktop application used by system administrat…
Apache Ant could leak sensitive information or be made to run programs as your login.
It was discovered that the SocketServer class included in apache-log4j1.2, a logging library for java, is vulnerable to deserialization of untrusted data. An a…
The package apache before version 2.4.43-1 is vulnerable to multiple issues including information disclosure and open redirect.
Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 2 zip release for RHEL 6, RHEL 7 and Microsoft Windows is available. Red Hat Product Securit…
Multiple vulnerabilities have been found in Apache Tomcat, the worst of which could lead to arbitrary code execution.
An issue has been found in libapache2-mod-auth-openidc, an OpenID Connect authentication module for Apache. Due to insufficient validatation of URLs an Open Re…
If your web server is running on Apache Tomcat, you should immediately install the latest available version of the server application to prevent hackers from t…
Apache Solr could be made to run programs if it received specially crafted network traffic.
Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 1 zip release for RHEL 6, RHEL 7 and Microsoft Windows is available. Red Hat Product Securit…
apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) SL7 noarch apache-commons-beanutils-1.8.3-15.…