All CosmicBytez Labs articles tagged #Apache, across news, security advisories, how-to guides, and projects.
A critical deserialization vulnerability in Apache Fury allows attackers to bypass class-registration checks during Java lambda deserialization, enabling arbitrary code execution. Upgrade to version 1.4.0 immediately.
Apache Tomcat's EncryptInterceptor cluster encryption feature has been insufficiently documented since version 9.0.13, leaving deployments vulnerable to...
Critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.5. Users must upgrade...
A second critical path traversal vulnerability (CVSS 9.1) in Apache IoTDB affects versions 1.0.0 through 1.3.5 and 2.0.0 through 2.0.6. Patch to 1.3.6 or...
The Apache Software Foundation has released urgent security updates for the Apache HTTP Server addressing a severe vulnerability in the HTTP/2 protocol...