Vulnerabilities in Apache Software Foundation

1,884 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-42250Possible log injectionEPSS 1.8%CVE-2016-8748In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessedEPSS 1.8%CVE-2018-8025CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-conEPSS 1.8%CVE-2023-39410Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDKEPSS 1.8%CVE-2018-8042Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when thEPSS 1.8%CVE-2022-41131HIGHApache Airflow Hive Provider vulnerability (command injection via hive_cli connection)EPSS 1.8%CVE-2017-12613When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and EPSS 1.7%CVE-2023-46302Apache Submarine: Fix CVE-2022-1471 SnakeYaml unsafe deserializationEPSS 1.7%CVE-2022-39944HIGHThe Apache Linkis JDBC EngineConn module has a RCE VulnerabilityEPSS 1.7%CVE-2021-43980LOWApache Tomcat: Information disclosureEPSS 1.7%CVE-2020-13922Apache DolphinScheduler (incubating) Permission vulnerabilityEPSS 1.7%CVE-2022-31781Regular Expression Denial of Service (ReDoS) in ContentType.java. (GHSL-2022-022)EPSS 1.7%CVE-2024-29133MEDIUMApache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object treeEPSS 1.7%CVE-2024-39877HIGHApache Airflow: DAG Author Code Execution possibility in airflow-schedulerEPSS 1.7%CVE-2023-51784CRITICALApache InLong: Remote Code Execution vulnerability in Apache InLong ManagerEPSS 1.7%CVE-2024-31865MEDIUMApache Zeppelin: Cron arbitrary user impersonation with improper privilegesEPSS 1.7%CVE-2022-28220STARTTLS command injection in Apache JAMESEPSS 1.7%CVE-2024-36387MEDIUMApache HTTP Server: DoS by Null pointer in websocket over HTTP/2EPSS 1.7%CVE-2023-44981CRITICALApache ZooKeeper: Authorization bypass in SASL Quorum Peer AuthenticationEPSS 1.7%CVE-2021-45230Apache Airflow: Creating DagRuns didn't respect Dag-level permissions in the WebserverEPSS 1.7%