Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-11775TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM aEPSS 7.0%CVE-2018-8005When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause perforEPSS 6.9%CVE-2021-30639DoS after non-blocking IO errorEPSS 6.9%CVE-2018-11796In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() EPSS 6.9%CVE-2016-5397The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tEPSS 6.9%CVE-2017-5656Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means EPSS 6.8%CVE-2018-8018In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/EPSS 6.8%CVE-2018-8009Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the ziEPSS 6.7%CVE-2021-29262Misapplied Zookeeper ACLs can result in leakage of configured authentication and authorization settingsEPSS 6.7%CVE-2022-34305XSS in examples web applicationEPSS 6.7%CVE-2021-22696OAuth 2 authorization service vulnerable to DDos attacksEPSS 6.6%CVE-2021-37579Bypass deserialization checks in Apache DubboEPSS 6.6%CVE-2017-3163When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts aEPSS 6.6%CVE-2021-30638An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and laterEPSS 6.6%CVE-2020-1931A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be confEPSS 6.5%CVE-2016-8734Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-serviEPSS 6.4%CVE-2021-44140Arbitrary file deletion on logoutEPSS 6.4%CVE-2018-1295In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, whicEPSS 6.3%CVE-2017-3156The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signatEPSS 6.3%CVE-2018-8004There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATSEPSS 6.3%