Vulnerabilidades em Apache Software Foundation

2.398 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-45106HIGHApache Ozone: Improper authentication when generating S3 secretsEPSS 0.6%CVE-2026-58185HIGHApache Traffic Server: Use-after-free in the intercept pluginEPSS 0.6%CVE-2026-50622HIGHApache Atlas: Missing Authorization on Admin EndpointsEPSS 0.6%CVE-2026-42809CRITICALApache Polaris: staged table creation could vend storage credentials for unvalidated locationsEPSS 0.6%CVE-2026-47342HIGHApache OFBiz: Privilege Escalation via updateOrRemove Authorization BypassEPSS 0.6%CVE-2024-41909MEDIUMApache MINA SSHD: integrity check bypassEPSS 0.6%CVE-2026-49050HIGHApache DolphinScheduler: General user can mint admin access tokens via /access-tokensEPSS 0.6%CVE-2026-58160MEDIUMApache Traffic Server: Out-of-bounds reads while parsing DNS responsesEPSS 0.6%CVE-2026-57866HIGHApache Impala: Secrets Exfiltration via SSRFEPSS 0.6%CVE-2026-49231LOWApache APISIX: Identity spoofing issue in APISIX opa pluginEPSS 0.6%CVE-2026-48911HIGHApache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation FlowEPSS 0.6%CVE-2025-55673MEDIUMApache Superset: Metadata exposure in embedded chartsEPSS 0.6%CVE-2026-49365MEDIUMApache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clientsEPSS 0.6%CVE-2026-56139MEDIUMApache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clientsEPSS 0.6%CVE-2026-75099MEDIUMApache Allura: Unauthenticated REST disclosureEPSS 0.6%CVE-2026-66390MEDIUMApache Wicket: crafted Link URL strings can break out of the JavaScript sequenceEPSS 0.6%CVE-2026-42509MEDIUMApache Wicket: crafted strings can break out of the JavaScript sequenceEPSS 0.6%CVE-2026-25688MEDIUMApache Answer: XSS in AI Answer RenderingEPSS 0.6%CVE-2026-25699MEDIUMApache Answer: Authorization Bypass in Timeline APIEPSS 0.6%CVE-2026-76986MEDIUMApache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValueEPSS 0.6%