Vulnerabilities in Apache Software Foundation

1,884 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-31779Improper HTTP/2 scheme and method validationEPSS 1.9%CVE-2022-47184HIGHApache Traffic Server: The TRACE method can be use to disclose network informationEPSS 1.9%CVE-2022-36760CRITICALApache HTTP Server: mod_proxy_ajp Possible request smugglingEPSS 1.9%CVE-2023-22887Apache Airflow path traversal by authenticated userEPSS 1.9%CVE-2018-11783sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin.EPSS 1.9%CVE-2022-39135Apache Calcite: potential XEE attacksEPSS 1.9%CVE-2021-27644DolphinScheduler mysql jdbc connector parameters deserialize remote code executionEPSS 1.9%CVE-2022-30973Missing fix for CVE-2022-30126 in 1.28.2EPSS 1.9%CVE-2017-15700A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, thEPSS 1.9%CVE-2021-37533MEDIUMApache Commons Net's FTP client trusts the host from PASV response by defaultEPSS 1.9%CVE-2024-26280MEDIUMApache Airflow: Overly broad default permissions for Viewer/Ops (audit logs)EPSS 1.9%CVE-2022-46751HIGHApache Ivy: XML External Entity vulnerability in Apache IvyEPSS 1.9%CVE-2023-42794Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on WindowsEPSS 1.9%CVE-2022-31780HTTP/2 framing vulnerabilitiesEPSS 1.8%CVE-2022-28129Insufficient Validation of HTTP/1.x HeadersEPSS 1.8%CVE-2023-28708MEDIUMApache Tomcat: JSESSIONID Cookie missing secure attribute in some configurationsEPSS 1.8%CVE-2023-38435Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole pluginEPSS 1.8%CVE-2023-25692HIGHApache Airflow Google Provider: Google Cloud Sql Provider Denial Of ServiceEPSS 1.8%CVE-2017-5658The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This cEPSS 1.8%CVE-2021-25642Apache Hadoop YARN remote code execution in ZKConfigurationStore of capacity schedulerEPSS 1.8%