Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ícaro Torres

#19598of 56,337
14.8Total CVSS
Vulnerabilities · 2
High
2
PT-2026-65742
7.3
2026-07-29
Apache · Apache Kyuubi · CVE-2026-23904
**Name of the Vulnerable Software and Affected Versions** Apache Kyuubi versions 1.8.0 through 1.11.x **Description** The Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the server to send HTTP requests to arbitrary reachable hosts, leading to Server-Side Request Forgery (SSRF), where the server is tricked into making requests to internal or external resources, or open-proxy behavior. **Recommendations** Upgrade to version 1.12.0. To restore proxied Engine UI after upgrading, set `kyuubi.frontend.rest.engine.ui.proxy.enabled` to true and configure allowed target hosts using `kyuubi.frontend.rest.engine.ui.proxy.hosts`.
PT-2024-31772
7.5
2024-11-16
Apache · Apache Hertzbeat · CVE-2024-45791
Name of the Vulnerable Software and Affected Versions: Apache HertzBeat versions prior to 1.6.1 Description: The issue is related to the exposure of sensitive information to an unauthorized actor. This is a problem of sensitive data exposure. Recommendations: For Apache HertzBeat versions prior to 1.6.1, upgrade to version 1.6.1 to fix the issue.