Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-40145CRITICALApache Karaf: JDBC JAAS LDAP injectionEPSS 2.4%CVE-2021-43410airavata-django-portal allows CRLF log injection because of the lack of escaping in the log statementsEPSS 2.4%CVE-2021-36161Unprotected input value toString cause RCEEPSS 2.4%CVE-2022-25757Apache APISIX: the body_schema check in request-validation plugin can be bypassedEPSS 2.4%CVE-2018-1298A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocEPSS 2.4%CVE-2018-8008Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that EPSS 2.4%CVE-2023-39508HIGHApache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledgesEPSS 2.4%CVE-2023-34212Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS ComponentsEPSS 2.4%CVE-2022-39198CRITICALApache Dubbo Hession Deserialization Vulnerability Gadgets BypassEPSS 2.4%CVE-2021-38542Apache James vulnerable to STARTTLS command injection (IMAP and POP3)EPSS 2.3%CVE-2017-7664Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.EPSS 2.3%CVE-2021-36739MEDIUMXSS vulnerability in the MVCBean JSP portlet maven archetypeEPSS 2.3%CVE-2021-45457Overly broad CORS configurationEPSS 2.3%CVE-2021-43082heap-buffer-overflow with stats-over-http pluginEPSS 2.3%CVE-2021-36738XSS vulnerability in the JSP version of the Apache Pluto Applicant MVCBean CDI portletEPSS 2.3%CVE-2021-36737XSS in V3 Demo PortletEPSS 2.3%CVE-2024-52338CRITICALApache Arrow R package: Arbitrary code execution when loading a malicious data fileEPSS 2.3%CVE-2022-42890Apache Batik prior to 1.16 allows RCE via scriptingEPSS 2.3%CVE-2022-28890Processing external DTDsEPSS 2.3%CVE-2021-41532Unauthenticated access to Ozone Recon HTTP endpointsEPSS 2.3%