Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-1294If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and thatEPSS 2.9%CVE-2021-40110Apache James IMAP vulnerable to a ReDoSEPSS 2.9%CVE-2017-7685Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.EPSS 2.9%CVE-2020-17529Apache NuttX (incubating) Out of Bound Write from invalid fragmentation offset value specified in the IP headerEPSS 2.9%CVE-2017-5640It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemoEPSS 2.9%CVE-2021-27576Apache OpenMeetings: bandwidth can be overloaded with public web serviceEPSS 2.8%CVE-2022-42920Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writingEPSS 2.8%CVE-2022-22932Path traversal flawsEPSS 2.8%CVE-2020-1925Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends aEPSS 2.8%CVE-2021-26544Apache Livy (Incubating) is vulnerable to cross site scriptingEPSS 2.8%CVE-2021-36163Unsafe deserialization in providers using the Hessian protocolEPSS 2.8%CVE-2017-7684Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple laEPSS 2.8%CVE-2020-1933A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware autEPSS 2.8%CVE-2022-26779Apache Cloudstack insecure random number generation affects project email invitationEPSS 2.8%CVE-2021-26559CWE-284 Improper Access Control on Configurations Endpoint for the Stable APIEPSS 2.8%CVE-2017-5649Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users wEPSS 2.8%CVE-2022-45462CRITICALApache DolphinScheduler prior to 2.0.5 have command execution vulnerabilityEPSS 2.8%CVE-2023-28706CRITICALApache Airflow Hive Provider Beeline Remote Command ExecutionEPSS 2.8%CVE-2018-17193The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected EPSS 2.8%CVE-2021-28657Infinite loop in Apache Tika's MP3 parserEPSS 2.8%