Vulnerabilities in Apache Software Foundation

2,378 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-5662—In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send malicioEPSS 4.1%CVE-2021-37578—Remote code execution via RMIEPSS 4.1%CVE-2026-40466HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URIEPSS 4.1%CVE-2026-50229MEDIUMApache Tomcat: XSS in number guess exampleEPSS 4.1%CVE-2021-30179—Apache Dubbo Pre-auth RCE via Java deserialization in the Generic filterEPSS 4.1%CVE-2022-32533CRITICALApache Portals Jetspeed XSS, CSRF, SSRF, and XXE issuesEPSS 4.1%CVE-2022-40189CRITICALApache Airlfow Pig Provider RCEEPSS 4.1%CVE-2018-8019—When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This alloEPSS 4.1%CVE-2020-13924—In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directEPSS 4.0%CVE-2021-33191—MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocolEPSS 4.0%CVE-2018-11778—UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions pEPSS 4.0%CVE-2020-9494—Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cEPSS 4.0%CVE-2020-1928—An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugginEPSS 4.0%CVE-2018-8030—A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to puEPSS 3.9%CVE-2021-26118—Flaw in ActiveMQ Artemis OpenWire supportEPSS 3.9%CVE-2018-8010—This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solEPSS 3.9%CVE-2023-38709HIGHApache HTTP Server: HTTP response splittingEPSS 3.9%CVE-2021-33036—Apache Hadoop Privilege escalation vulnerabilityEPSS 3.9%CVE-2017-3161—The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.EPSS 3.9%CVE-2021-40439—Billion LaughsEPSS 3.9%