Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-25312An XML external entity (XXE) injection vulnerability exists in the Apache Any23 RDFa XSLTStylesheet extractorEPSS 2.7%CVE-2021-42009Apache Traffic Control Traffic Ops Email Injection VulnerabilityEPSS 2.7%CVE-2016-8746Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recuEPSS 2.7%CVE-2023-47804Apache OpenOffice: Macro URL arbitrary script executionEPSS 2.7%CVE-2022-42468CRITICALApache Flume prior to 1.11.0 has an Improper Input Validation (JNDI Injection) in JMSSourceEPSS 2.7%CVE-2022-23913Apache ActiveMQ Artemis DoSEPSS 2.7%CVE-2021-35474Dynamic stack buffer overflow in cachekey pluginEPSS 2.7%CVE-2022-27479SQL injection vulnerability in chart data APIEPSS 2.7%CVE-2019-0187Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connecEPSS 2.7%CVE-2021-28544Apache Subversion SVN authz protected copyfrom paths regressionEPSS 2.7%CVE-2021-33190Bypass network access controlEPSS 2.7%CVE-2018-17192The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some broEPSS 2.7%CVE-2018-1289In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to queEPSS 2.7%CVE-2017-7663Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.EPSS 2.7%CVE-2021-38555An XML external entity (XXE) injection vulnerability exists in Apache Any23 StreamUtils.javaEPSS 2.7%CVE-2023-37895CRITICALApache Jackrabbit RMI access can lead to RCEEPSS 2.7%CVE-2023-46589HIGHApache Tomcat: HTTP request smuggling via malformed trailer headersEPSS 2.7%CVE-2018-1339A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.EPSS 2.6%CVE-2017-15695When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to dEPSS 2.6%CVE-2017-15712Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. TEPSS 2.6%