Vulnerabilities in Apache Software Foundation

1,894 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-11799Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML thEPSS 1.5%CVE-2018-1332Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to iEPSS 1.5%CVE-2024-23807HIGHApache Xerces C++: Use-after-free on external DTD scanEPSS 1.5%CVE-2017-9796When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster mEPSS 1.5%CVE-2023-40712Apache Airflow: Secrets can be unmasked in the "Rendered Template" EPSS 1.5%CVE-2023-27296HIGHApache InLong: JDBC Deserialization Vulnerability in InLongEPSS 1.5%CVE-2022-46365CRITICALApache StreamPark (incubating): Logic error causing any account resetEPSS 1.5%CVE-2022-31777MEDIUMApache Spark XSS vulnerability in log viewer UI JavascriptEPSS 1.5%CVE-2022-24963CRITICALApache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functionsEPSS 1.5%CVE-2023-39913HIGHApache UIMA Java SDK Core, Apache UIMA Java SDK CPE, Apache UIMA Java SDK Vinci adapter, Apache UIMA Java SDK tools: Potential untrusted code execution when deserializing certain binary CAS formatsEPSS 1.5%CVE-2024-27905CRITICALApache Aurora: padding oracle can allow construction an authentication cookieEPSS 1.5%CVE-2022-45910MEDIUMApache ManifoldCF: LDAP Injection Vulnerability - ActiveDirectory AuthoritiesEPSS 1.5%CVE-2023-29246HIGHApache OpenMeetings: allows null-byte InjectionEPSS 1.5%CVE-2024-23945MEDIUMApache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification failsEPSS 1.5%CVE-2023-26513HIGHApache Sling Resource Merger: Requests to certain paths managed by the Apache Sling Resource Merger can lead to DoSEPSS 1.5%CVE-2024-29735MEDIUMApache Airflow: Potentially harmful permission changing by log task handlerEPSS 1.5%CVE-2021-42010CRITICALCRLF log injectionEPSS 1.5%CVE-2024-53299MEDIUMApache Wicket: An attacker can intentionally trigger a memory leakEPSS 1.5%CVE-2024-24746HIGHApache NimBLE: Denial of service in NimBLE Bluetooth stackEPSS 1.5%CVE-2021-41831Timestamp Manipulation with Signature WrappingEPSS 1.5%