Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-23672MEDIUMApache Tomcat: WebSocket DoS with incomplete closing handshakeEPSS 2.3%CVE-2022-34916Improper Input Validation (JNDI Injection) in JMSMessageConsumerEPSS 2.3%CVE-2018-11777In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if rangerEPSS 2.3%CVE-2023-49109CRITICALRemote Code Execution in Apache DolphinschedulerEPSS 2.3%CVE-2023-49898Apache StreamPark (incubating): Authenticated system users could trigger remote command executionEPSS 2.3%CVE-2021-39231Missing authentication/authorization on internal RPC endpointsEPSS 2.3%CVE-2021-39233Container-related datanode operations can be called without authorizationEPSS 2.3%CVE-2015-5241After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users toEPSS 2.3%CVE-2018-8016The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, whichEPSS 2.3%CVE-2018-1319In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL,EPSS 2.3%CVE-2021-31164Apache Unomi log injectionEPSS 2.3%CVE-2022-37021Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8.EPSS 2.3%CVE-2023-25754CRITICALApache Airflow: Privilege escalation using airflow logsEPSS 2.3%CVE-2018-1284In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_floEPSS 2.3%CVE-2020-17517Ozone S3 Gateway allows bucket and key access to non authenticated usersEPSS 2.3%CVE-2017-7671There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This isEPSS 2.3%CVE-2017-15713Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to exEPSS 2.3%CVE-2022-45378CRITICALApache SOAP allows unauthenticated users to potentially invoke arbitrary codeEPSS 2.3%CVE-2022-32549log injection in Sling loggingEPSS 2.2%CVE-2022-24948Apache JSPWiki Cross-site scripting vulnerability on User Preferences screenEPSS 2.2%