
Vulnerabilità che ho segnalato alla Apache Software Foundation: 46 CVE in 15 progetti
Vulnerabilità che ho segnalato alla Apache Software Foundation, divulgate attraverso il processo di sicurezza ASF. 46 CVE su 15 progetti, dal 2023 al 2026.
Dove esiste un reproducer pubblico, questo è collegato. Ognuno è un progetto minimale e autonomo che dimostra il problema e indica la release che lo ha risolto.
Su 25 CWE distinte, due classi dominano: deserializzazione di dati non attendibili (7) e server-side request forgery (7).
| CVE | Componente | Classe | Risolto in | PoC |
|---|---|---|---|---|
| CVE-2023-41313 | Doris | CWE-208 Observable Timing Discrepancy | 1.2.8 | - |
| CVE-2023-41834 | Flink Stateful Functions | CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component | 3.3.0 | - |
| CVE-2023-43123 | Storm | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | 2.6.0 | - |
| CVE-2024-23454 | Hadoop | CWE-378 Creation of Temporary File With Insecure Permissions | 3.4.0 | - |
| CVE-2024-23953 | Hive | CWE-208 Observable Timing Discrepancy | 4.0.0 | - |
| CVE-2024-29869 | Hive | CWE-732 Incorrect Permission Assignment for Critical Resource | 4.0.1 | - |
| CVE-2026-28672 | Ranger | CWE-77 Improper Neutralization of Special Elements used in a Command | 2.9.0 | reproducer |
| CVE-2026-34476 | SkyWalking MCP | CWE-918 Server-Side Request Forgery | non pubblicata | - |
| CVE-2026-40005 | IoTDB | CWE-22 Improper Limitation of a Pathname to a Restricted Directory | 2.0.10 | - |
| CVE-2026-40008 | IoTDB | CWE-470 Use of Externally-Controlled Input to Select Classes or Code | 2.0.10 | - |
| CVE-2026-40564 | Flink Kubernetes Operator | CWE-918 Server-Side Request Forgery | 1.15.0 | reproducer |
| CVE-2026-41041 | Gravitino | CWE-177 Improper Handling of URL Encoding | 1.2.1 | - |
| CVE-2026-44616 | Zeppelin | CWE-90 Improper Neutralization of Special Elements used in an LDAP Query | 0.12.1 | - |
| CVE-2026-49361 | Fluss (incubating) | CWE-400 Uncontrolled Resource Consumption | non pubblicata | - |
| CVE-2026-63039 | InLong | CWE-89 Improper Neutralization of Special Elements used in an SQL Command | 2.4.0 | reproducer |
| CVE-2026-64640 | Polaris | CWE-863 Incorrect Authorization | 1.7.0 | reproducer |
Camel è il progetto che mantengo, quindi è quello che riceve il maggior scrutinio. Il pattern dominante è header in ingresso non filtrati che raggiungono il control plane di un producer, più una lunga coda di deserializzazione non sicura nei percorsi di registry e migrazione.