Apache Aurora vulnerabilities
2 known vulnerabilities affecting apache/aurora.
Total CVEs
2
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2024-27905CRITICALCVSS 9.1≥ 0.5.02024-02-27
CVE-2024-27905 [CRITICAL] CWE-200 CVE-2024-27905: ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerabi
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora.
An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a valid authentication cookie. Potentially this could be combined with vulnerabilities in o
nvd
CVE-2016-4437CRITICALCVSS 9.8KEVPoC≥ 0.10.0, < 0.18.12016-06-07
CVE-2016-4437 [CRITICAL] CWE-321 CVE-2016-4437: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature,
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
nvd