Vulnerabilities in Apache Software Foundation

1,894 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-25763MEDIUMImproper input validation on HTTP/2 headers EPSS 1.6%CVE-2023-25691CRITICALApache Airflow Google Provider: Google Cloud Sql Provider Remote Command ExecutionEPSS 1.6%CVE-2024-50306CRITICALApache Traffic Server: Server process can fail to drop privilegeEPSS 1.6%CVE-2017-9792In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table daEPSS 1.6%CVE-2022-28331CRITICALApache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv functionEPSS 1.6%CVE-2024-34693MEDIUMApache Superset: Server arbitrary file readEPSS 1.6%CVE-2025-59118HIGHApache OFBiz: Critical Remote Command Execution via Unrestricted File UploadEPSS 1.6%CVE-2023-50298HIGHApache Solr: Solr can expose ZooKeeper credentials via Streaming ExpressionsEPSS 1.6%CVE-2024-32077MEDIUMApache Airflow: XSS vulnerability in Task Instance Log/Log DetailsEPSS 1.6%CVE-2022-32287HIGHApache UIMA prior to 3.3.1 has a path traversal vulnerability when extracting (PEAR) archivesEPSS 1.6%CVE-2023-22602Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP requestEPSS 1.6%CVE-2022-35724Denial of service while reading data in Avro Rust SDKEPSS 1.6%CVE-2023-42663Apache Airflow: Bypass permission verification to view task instances of other dagsEPSS 1.6%CVE-2021-28655MEDIUMApache Zeppelin: Arbitrary file deletion vulnerabilityEPSS 1.5%CVE-2024-40898CRITICALApache HTTP Server: SSRF with mod_rewrite in server/vhost context on WindowsEPSS 1.5%CVE-2023-34478CRITICALApache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.EPSS 1.5%CVE-2023-33234HIGHApache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configurationEPSS 1.5%CVE-2022-40604HIGHFormat String VulnerabilityEPSS 1.5%CVE-2023-22886HIGHApache Airflow JDBC Provider: RCE VulnerabilityEPSS 1.5%CVE-2022-45136CRITICALApache Jena SDB allows arbitrary deserialisation via JDBCEPSS 1.5%