The Apache Software Foundation reported handling 376 new vulnerability reports across 101 top-level projects in 2020, closing 341 cases and assigning 151 CVEs while adopting new tooling and the CVE automation API to speed disclosure. The report highlighted several high-profile issues, including the Apache Struts flaw tracked as CVE-2019-0230, where forced double OGNL evaluation in tag attributes can lead to remote code execution in Struts 2.0.0 through 2.5.20, alongside other notable Apache security events that drew public exploit or proof-of-concept attention.
Additional disclosures tied to that period included two Apache Flink directory traversal bugs, CVE-2020-17518 and CVE-2020-17519, affecting exposed REST APIs and enabling arbitrary file write or read access on vulnerable JobManager hosts; Apache said users should upgrade to Flink 1.11.3 or 1.12.0. Apache also published CVE-2020-13951, a denial-of-service issue in the public NetTest web service of Apache OpenMeetings 4.0.0 through 5.0.0, and CVE-2019-0235, a CSRF flaw in Apache OFBiz 17.12.01, underscoring the breadth of web, file-system, and application-layer risks disclosed across Apache projects.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2020-17518 was updated. The entry continued to document the Apache Flink arbitrary file-write vulnerability and related references.
The CVE record for CVE-2020-17519 was updated. The record retained details on the Apache Flink arbitrary file-read vulnerability and its remediation guidance.
The CVE record for CVE-2019-0230 was updated. The updated record continued to reference downstream Oracle and SAP advisories and public exploit-related writeups.
The CVE record for CVE-2019-0235 was updated. The record includes references to Apache security report announcements from January 25 and February 23, 2021.
The CVE record for CVE-2020-13951 was updated. The entry references Apache security report messages published on January 25 and February 23, 2021.
A CVE record was published for CVE-2020-17519, describing a directory traversal vulnerability in Apache Flink 1.11.0 through 1.11.2 that allows arbitrary file reads via the JobManager REST API. Apache advised exposed users to upgrade to 1.11.3 or 1.12.0.
Apache announced CVE-2020-17518 on Flink development, user, and announce mailing lists, and the issue was also referenced on the oss-security mailing list. Follow-up discussion and JIRA activity for FLINK-20875 continued during January 2021.
A CVE record was published for CVE-2020-17518, describing a directory traversal vulnerability in Apache Flink 1.5.1 through 1.11.2 that can enable remote file writing through the REST API. Apache advised exposed users to upgrade to 1.11.3 or 1.12.0.
The Apache Software Foundation released its 2020 security report in January 2021, summarizing 376 new vulnerability reports across 101 top-level projects in 2020 and 151 assigned CVEs from 341 closed reports. The report also highlighted public exploit activity affecting several Apache projects, including OpenMeetings, OFBiz, Struts, and Flink.
The Apache Software Foundation became the first organization to obtain a live CVE identifier using the new CVE automation API. ASF said the automation was intended to speed public CVE publication.
The Apache Software Foundation released an internal tool to help projects edit, validate, and submit CVE entries to MITRE. The change was highlighted as a process improvement in ASF's 2020 security reporting.
A CVE record was published for CVE-2020-13951, describing a denial-of-service issue in the public NetTest web service of Apache OpenMeetings 4.0.0 through 5.0.0. The Apache Software Foundation was listed as the CNA.
A CVE record was published for CVE-2019-0230, covering a forced double OGNL evaluation issue in Apache Struts 2.0.0 through 2.5.20 that may lead to remote code execution. The record references Apache's S2-059 advisory.
Apache mailing list entries dated July 5 through July 8, 2020 discussed a proof of concept for the CSRF token issue tied to CVE-2019-0235, including an ofbiz-commits entry documenting the PoC under OFBIZ-11306.
A CVE record was published for CVE-2019-0235, describing a cross-site request forgery vulnerability affecting Apache OFBiz 17.12.01. The Apache Software Foundation was listed as the CNA.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcelists.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.