Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-45143Apache Tomcat: JsonErrorReportValve escapingEPSS 2.5%CVE-2022-30126Apache Tika Regular Expression Denial of Service in Standards ExtractorEPSS 2.5%CVE-2018-17186An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, EPSS 2.5%CVE-2021-39236Owners of the S3 tokens are not validatedEPSS 2.5%CVE-2024-22393CRITICALApache Answer: Pixel Flood Attack by uploading the large pixel fileEPSS 2.5%CVE-2021-38295Privilege escalation vulnerability when using HTML attachmentsEPSS 2.5%CVE-2020-1926Timing attack in Cookie signature verificationEPSS 2.5%CVE-2018-11792In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as havEPSS 2.5%CVE-2024-38474HIGHApache HTTP Server weakness with encoded question marks in backreferencesEPSS 2.5%CVE-2017-7687When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1EPSS 2.4%CVE-2021-32567Reading HTTP/2 frames too many timesEPSS 2.4%CVE-2017-9790When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3EPSS 2.4%CVE-2021-36372Original block tokens are persisted and can be retrievedEPSS 2.4%CVE-2021-37147Request Smuggling - LF line endingEPSS 2.4%CVE-2022-26650Apache ShenYu (incubating) Regular expression denial of serviceEPSS 2.4%CVE-2024-52577CRITICALApache Ignite: Possible RCE when deserializing incoming messages by the server nodeEPSS 2.4%CVE-2022-29265Improper Restriction of XML External Entity References in Multiple ComponentsEPSS 2.4%CVE-2016-6807Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operatiEPSS 2.4%CVE-2021-26558Deserialization of Untrusted DataEPSS 2.4%CVE-2021-41585ATS stops accepting connections on FreeBSDEPSS 2.4%