Vulnerabilities in Apache Software Foundation

1,877 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-40664CRITICALAuthentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcherEPSS 2.2%CVE-2017-9803Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-EPSS 2.2%CVE-2019-0231Apache MINA SSLFilter security IssueEPSS 2.2%CVE-2022-24289Deserialization of untrusted data in the Hessian Component of Apache Cayenne 4.1 with older Java versionsEPSS 2.2%CVE-2017-5654In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to EPSS 2.2%CVE-2022-47937CRITICALMultiple parsing problems in the Apache Sling Commons JSON moduleEPSS 2.2%CVE-2022-36364Apache Calcite Avatica JDBC driver `httpclient_impl` connection property can be used as an RCE vectorEPSS 2.2%CVE-2017-17836In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases usedEPSS 2.2%CVE-2025-48924MEDIUMApache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputsEPSS 2.2%CVE-2018-1292Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL EPSS 2.2%CVE-2023-42795MEDIUMApache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requestsEPSS 2.2%CVE-2023-28710HIGHApache Airflow Spark Provider Arbitrary File Read via JDBCEPSS 2.2%CVE-2024-43202CRITICALApache DolphinScheduler: Remote Code Execution VulnerabilityEPSS 2.1%CVE-2024-45505HIGHApache HertzBeat: Exists Native Deser RCE and file writing vulnerabilitiesEPSS 2.1%CVE-2022-41704HIGHApache Batik prior to 1.16 allows RCE when loading untrusted SVG inputEPSS 2.1%CVE-2022-38398Server-Side Request Forgery Information Disclosure VulnerabilityEPSS 2.1%CVE-2021-32565HTTP Request Smuggling, content length with invalid chartersEPSS 2.1%CVE-2023-27522HIGHApache HTTP Server: mod_proxy_uwsgi HTTP response splittingEPSS 2.1%CVE-2016-8751Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store sEPSS 2.1%CVE-2024-36522CRITICALApache Wicket: Remote code execution via XSLT injectionEPSS 2.1%