Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-8022A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issEPSS 7.5%CVE-2022-40146Jar url should be blocked by DefaultScriptSecurityEPSS 7.4%CVE-2023-29234Bypass serialize checks in Apache DubboEPSS 7.4%CVE-2021-40690Bypass of the secureValidation propertyEPSS 7.4%CVE-2016-8739The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers EPSS 7.3%CVE-2023-41835HIGHApache Struts: excessive disk usageEPSS 7.3%CVE-2018-11788Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folEPSS 7.3%CVE-2020-11982An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, REPSS 7.2%CVE-2023-37924Apache Submarine: SQL injection from unauthorized loginEPSS 7.2%CVE-2017-12634The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerabEPSS 7.2%CVE-2016-6817HIGHThe HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that waEPSS 7.2%CVE-2021-41079Apache Tomcat DoS with unexpected TLS packetEPSS 7.2%CVE-2018-8040Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This afEPSS 7.2%CVE-2016-6794When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In EPSS 7.2%CVE-2024-32114HIGHApache ActiveMQ: Jolokia and REST API were not secured with default configurationEPSS 7.1%CVE-2017-12633The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulneraEPSS 7.1%CVE-2016-8747HIGHAn information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. HEPSS 7.1%CVE-2020-1930A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can beEPSS 7.1%CVE-2017-12621During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entityEPSS 7.0%CVE-2021-30468Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriterEPSS 7.0%