High
Apache Cayenne could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the Hessian Component. By sending a specially-crafted payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache APISIX could allow a remote attacker to execute arbitrary code on the system, caused by an IP restriction of Admin API bypass flaw. By sending specially-crafted requests using the batch-requests plugin, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache Cassandra could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a flaw when include configurations for enable_user_defined_functions: true, enable_scripted_user_defined_functions: true, and enable_user_defined_functions_threads: flase. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache
Upgrade to the latest version of Apache, available from the Apache Web site.
Apache Cayenne
Apache APISIX
Apache Cassandra