apache http server
500 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
SmtpHook called Python's smtplib.SMTP.starttls() without an SSL context, so no certificate valiaccess_key and connection_string connection properties were not marked as sensitive names in secrets masker. This means th/api/v2/dagReports could perform Dag code execution in the context of the api-server if the api-server was deployeexample_dag_decorator had non-validated parameter that allowed the UI user to redirect the example to a maliciouscan write on dataset and without all data access permissions, allows for users to/login endpoint./confirm endpoint.origin qu/confirm endpoint.database webserver session backend was susceptible to session fixation.origin query argument. This i