Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-47561CRITICALApache Avro Java SDK: Arbitrary Code Execution when reading Avro schema (Java SDK)EPSS 3.3%CVE-2022-25168Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTarEPSS 3.3%CVE-2020-13929Notebook permissions bypassEPSS 3.3%CVE-2018-11766In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbEPSS 3.2%CVE-2020-17532Apache ServiceComb Yaml remote deserialization vulnerabilityEPSS 3.2%CVE-2021-27578Cross Site Scripting in markdown interpreterEPSS 3.2%CVE-2018-17188Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulEPSS 3.2%CVE-2022-38649CRITICALApache Airflow Pinot provider allowed Command InjectionEPSS 3.2%CVE-2021-33036Apache Hadoop Privilege escalation vulnerabilityEPSS 3.2%CVE-2019-12408It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had EPSS 3.2%CVE-2022-46421CRITICALApache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_paramsEPSS 3.2%CVE-2021-41616CRITICALApache ddlutils 1.0 readobject vulnerabilityEPSS 3.2%CVE-2017-15699A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remoteEPSS 3.2%CVE-2018-1316The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directoEPSS 3.2%CVE-2018-1310Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActEPSS 3.2%CVE-2025-49125HIGHApache Tomcat: Security constraint bypass for pre/post-resourcesEPSS 3.2%CVE-2022-32533CRITICALApache Portals Jetspeed XSS, CSRF, SSRF, and XXE issuesEPSS 3.2%CVE-2024-38477HIGHApache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious requestEPSS 3.2%CVE-2024-23946MEDIUMApache OFBiz: Path traversal or file inclusionEPSS 3.1%CVE-2012-3353The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files iEPSS 3.1%