;; ;; Licensed to the Apache Software Foundation (ASF) under one ;; or more contributor license agreements. See the NOTICE file ;; distributed with this work for additional information ;; regarding copyright ownership. The ASF licenses this file ;; to you under the Apache License, Version 2.0 (the ;; “License”); you may not use this file except in compliance ;; with the License. You may obtain a copy of the License at ;; ;; http://www.apache.org/licenses/LICENSE-2.0 ;; ;; Unless required by applicable law or agreed to in writing, ;; software distributed under the License is distributed on an ;; “AS IS” BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY ;; KIND, either express or implied. See the License for the ;; specific language governing permissions and limitations ;; under the License. ;;

Security

CVE-IDSeverityAffected versionsFixed versionsSummary
CVE-2016-3094Important6.0.0, 6.0.1, and 6.0.26.0.3Denial of service
CVE-2016-4432Important6.0.2 and earlier6.0.3Authentication bypass
CVE-2016-8741Moderate6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.06.0.6, 6.1.1Information leakage
CVE-2017-15701Important6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.46.1.5Denial of Service
CVE-2017-15702Important0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.326.0.0Authentication vulnerability
CVE-2018-1298Important7.0.07.0.1Denial of Service
CVE-2018-8030Important7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.47.0.5Denial of Service
CVE-2019-0200Important6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.07.0.7, 7.1.1Denial of Service

See the main security page for general information and details for other components.