Vulnerabilities in Apache Software Foundation

1,894 results
Vexday analysis

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-46769MEDIUMApache Sling App CMS: XSS in CMS Site Group DetailEPSS 1.4%CVE-2023-25695MEDIUMInformation disclosure in Apache AirflowEPSS 1.4%CVE-2021-39234Raw block data can be read bypassing ACL/authorizationEPSS 1.4%CVE-2023-40273HIGHSession fixation in Apache Airflow web interfaceEPSS 1.4%CVE-2024-31862MEDIUMApache Zeppelin: Denial of service with invalid notebook nameEPSS 1.4%CVE-2024-29834MEDIUMApache Pulsar: Improper Authorization For Namespace and Topic Management EndpointsEPSS 1.4%CVE-2017-9797When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode aEPSS 1.4%CVE-2023-49735Apache Tiles: Unvalidated input may lead to path traversal and XXEEPSS 1.4%CVE-2023-31066CRITICALApache InLong: Insecure direct object references for inlong sourcesEPSS 1.4%CVE-2022-40309MEDIUMApache Archiva prior to 2.2.9 allows an authenticated user to delete arbitrary directoriesEPSS 1.4%CVE-2022-36125HIGHInteger overflow when reading corrupted .avro file in Avro Rust SDKEPSS 1.4%CVE-2020-1932An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are ablEPSS 1.4%CVE-2023-37544HIGHApache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoSEPSS 1.4%CVE-2021-41830Double Certificate AttackEPSS 1.3%CVE-2023-47265Apache Airflow: DAG Params alllow to embed unchecked JavascriptEPSS 1.3%CVE-2024-27140MEDIUMApache Archiva: reflected XSSEPSS 1.3%CVE-2022-43766HIGHApache IoTDB prior to 0.13.3 allows DoSEPSS 1.3%CVE-2026-41293CRITICALApache Tomcat: HTTP/2 request headers not validatedEPSS 1.3%CVE-2023-40610MEDIUMApache Superset: Privilege escalation with default examples databaseEPSS 1.3%CVE-2024-32838CRITICALApache Fineract: SQL injection vulnerabilities in offices API endpointEPSS 1.3%