The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The Apache Software Foundation on Friday addressed a high severity vulnerability in Apache OFBiz that could have allowed an unauthenticated adversary to remote…
Apache Tika could be made to crash if it opened a specially crafted file.
Apache XML-RPC could be made to execute arbitrary code if it received specially crafted data by a malicious XML-RPC server.
Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.
If your web-server runs on Apache, you should immediately install the latest available version of the server application to prevent hackers from taking unautho…
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the serv…
Several security issues were fixed in Apache HTTP Server.
Several issues have been found in libapache2-mod-auth-openidc, the OpenID Connect authentication module for the Apache HTTP server.
Over the past few weeks, a heated debate has arisen on the Apache SpamAssassin users list regarding the replacement of racially charged terms like ''whitelist'…
A new research has uncovered multiple critical reverse RDP vulnerabilities in Apache Guacamole, a popular remote desktop application used by system administrat…
Apache Ant could leak sensitive information or be made to run programs as your login.
It was discovered that the SocketServer class included in apache-log4j1.2, a logging library for java, is vulnerable to deserialization of untrusted data. An a…
The package apache before version 2.4.43-1 is vulnerable to multiple issues including information disclosure and open redirect.
Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Re…
Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 2 zip release for RHEL 6, RHEL 7 and Microsoft Windows is available. Red Hat Product Securit…
For the first time ever, the Apache Pulsar PMC team is publishing a user survey report. The 2020 Apache Pulsar User Survey Report reveals Pulsar's accelerating…
Multiple vulnerabilities have been found in Apache Tomcat, the worst of which could lead to arbitrary code execution.
TLSv1.3 support has been enabled in Apache HTTP Server in Ubuntu 18.04 LTS.
An issue has been found in libapache2-mod-auth-openidc, an OpenID Connect authentication module for Apache. Due to insufficient validatation of URLs an Open Re…
If your web server is running on Apache Tomcat, you should immediately install the latest available version of the server application to prevent hackers from t…
One of the most significant projects from the Apache Foundation has released another version of SpamAssassin. This is primarily a security release, but also in…
Apache Solr could be made to run programs if it received specially crafted network traffic.
Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Re…
Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 1 zip release for RHEL 6, RHEL 7 and Microsoft Windows is available. Red Hat Product Securit…