Vulnerabilidades en Apache Software Foundation

2378 resultados
Análisis Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-40127HIGHApache Airflow <2.4.0 has an RCE in a bash exampleEPSS 85.7%CVE-2017-15715—In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, raEPSS 85.5%CVE-2021-31805—Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.EPSS 85.4%CVE-2022-28730—Apache JSPWiki Cross-site scripting vulnerability on AJAXPreview.jspEPSS 85.4%CVE-2022-27166—XSS vulnerability on XHRHtml2Markup.jsp in JSPWiki 2.11.2EPSS 85.4%CVE-2022-24697CRITICALApache Kylin prior to 4.0.2 allows command injection when the configuration overwrites function overwrites system parametersEPSS 84.8%CVE-2023-25690CRITICALApache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxyEPSS 84.5%CVE-2021-38294—Shell Command Injection Vulnerability in Nimbus Thrift ServerEPSS 84.5%CVE-2023-50386HIGHApache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSetsEPSS 83.7%CVE-2021-44224—Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierEPSS 82.3%CVE-2022-28732—Apache JSPWiki Cross-site scripting vulnerability on WeblogPluginEPSS 82.0%CVE-2022-45402MEDIUMApache Airflow: Open redirect during loginEPSS 81.8%CVE-2021-30128—Unsafe deserialization in Apache OFBizEPSS 81.2%CVE-2022-34169HIGHApache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheetsEPSS 81.0%CVE-2021-38540—Apache Airflow: Variable Import endpoint missed authentication checkEPSS 80.9%CVE-2021-36749—Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)EPSS 80.9%CVE-2023-50164—Apache Struts: File upload component had a directory traversal vulnerabilityEPSS 80.8%CVE-2021-4104HIGHDeserialization of untrusted data in JMSAppender in Apache Log4j 1.2EPSS 80.6%CVE-2024-56325CRITICALApache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not requiredEPSS 80.2%CVE-2016-8740—The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrictEPSS 79.1%