Vulnerabilities in Apache Software Foundation

1,884 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2016-8752Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointiEPSS 2.1%CVE-2023-35797CRITICALApache Airflow Hive Provider Beeline RCE with PrincipalEPSS 2.1%CVE-2021-40111Apache James IMAP parsing Denial Of ServiceEPSS 2.1%CVE-2023-29216CRITICALApache Linkis DatasourceManager module has a deserialization command executionEPSS 2.1%CVE-2023-29215CRITICALApache Linkis JDBC EngineCon has a deserialization command executionEPSS 2.1%CVE-2018-1291Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entitEPSS 2.1%CVE-2016-6803An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for WindEPSS 2.1%CVE-2018-1340Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, whEPSS 2.1%CVE-2017-5663In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read EPSS 2.1%CVE-2023-26031HIGHPrivilege escalation in Apache Hadoop Yarn container-executor binary on Linux systemsEPSS 2.1%CVE-2021-45458Hardcoded credentialsEPSS 2.1%CVE-2017-12622When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh EPSS 2.1%CVE-2021-25640Open Redirect or SSRF vulnerability usage of parseURLEPSS 2.1%CVE-2016-6815In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.EPSS 2.1%CVE-2023-30776MEDIUMApache Superset: Database connection password leakEPSS 2.1%CVE-2023-28707HIGHAirflow Apache Drill Provider Arbitrary File Read VulnerabilityEPSS 2.1%CVE-2017-5655In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The tempoEPSS 2.1%CVE-2024-29131HIGHApache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()EPSS 2.1%CVE-2017-3154Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.EPSS 2.1%CVE-2017-15720In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.EPSS 2.0%