Vulnerabilities in Apache

91 results
Vexday analysis

Das 89 CVEs catalogadas para o Apache, 4 estão confirmadas em exploração ativa pelo CISA KEV — uma taxa que supera em 10 vezes a média geral do catálogo, sinalizando risco operacional concreto e não apenas teórico. O tipo de falha mais recorrente é CWE-502 (desserialização de dados não confiáveis), classe historicamente associada a execução remota de código e de difícil mitigação sem correções estruturais. A CVE mais perigosa em atividade, CVE-2020-1938, apresenta EPSS de 0,9927, indicando probabilidade extremamente alta de exploração, e merece atenção prioritária em ambientes que ainda não aplicaram os controles correspondentes. A presença de 10 CVEs com PoC pública amplia a superfície de risco imediato, especialmente considerando que o EPSS máximo observado no conjunto chega a 0,9965.

CVE-2019-10070Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionalityEPSS 1.8%CVE-2011-2487The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a BlEPSS 1.8%CVE-2018-11774Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is theEPSS 1.4%CVE-2018-11772Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in theEPSS 1.4%CVE-2024-42362HIGHGHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/importEPSS 1.3%CVE-2019-10099Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true.EPSS 1.3%CVE-2024-42361HIGHGHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}EPSS 1.1%CVE-2020-1929The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration iEPSS 1.0%CVE-2018-11805In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exEPSS 0.9%CVE-2019-12400In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a sEPSS 0.8%CVE-2025-58712MEDIUMAmq: privilege escalation via excessive /etc/passwd permissionsEPSS 0.2%