Vulnerabilidades en Apache Software Foundation

2378 resultados
Análisis Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-46226CRITICALApache IoTDB: Remote Code Execution (RCE) risk via the UDFEPSS 1.9%CVE-2025-52434HIGHApache Tomcat: APR/Native Connector crash leading to DoSEPSS 1.9%CVE-2023-26464HIGHApache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppenderEPSS 1.9%CVE-2022-40705HIGHApache SOAP: XML External Entity Injection (XXE) allows unauthenticated users to read arbitrary files via HTTPEPSS 1.9%CVE-2018-11786—In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any useEPSS 1.9%CVE-2023-36542HIGHApache NiFi: Potential Code Injection with Properties Referencing Remote ResourcesEPSS 1.9%CVE-2024-27894HIGHApache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS ProxyingEPSS 1.9%CVE-2023-25693CRITICALSqoop Apache Airflow Provider Remote Code Execution VulnerabilityEPSS 1.9%CVE-2017-5642—During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.EPSS 1.9%CVE-2026-40453CRITICALApache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injectionEPSS 1.9%CVE-2022-39944HIGHThe Apache Linkis JDBC EngineConn module has a RCE VulnerabilityEPSS 1.9%CVE-2022-37865CRITICALApache Ivy allows creating/overwriting any file on the systemEPSS 1.9%CVE-2022-36760CRITICALApache HTTP Server: mod_proxy_ajp Possible request smugglingEPSS 1.9%CVE-2022-28889—Clickjacking in the web consoleEPSS 1.9%CVE-2018-11783—sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin.EPSS 1.9%CVE-2017-15700—A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, thEPSS 1.9%CVE-2023-40195HIGHApache Airflow Spark Provider Deserialization Vulnerability RCEEPSS 1.9%CVE-2022-38362—Docker Provider <3.0 RCE vulnerability in example dagEPSS 1.9%CVE-2024-26280MEDIUMApache Airflow: Overly broad default permissions for Viewer/Ops (audit logs)EPSS 1.9%CVE-2023-42794—Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on WindowsEPSS 1.9%