Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2016-8741The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among thEPSS 6.3%CVE-2017-3159Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can leadEPSS 6.3%CVE-2022-28615CRITICALRead beyond bounds in ap_strcmp_match()EPSS 6.3%CVE-2021-38153Timing Attack Vulnerability for Apache Kafka Connect and ClientsEPSS 6.3%CVE-2017-3162HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is notEPSS 6.3%CVE-2024-52316CRITICALApache Tomcat: Authentication bypass when using Jakarta Authentication APIEPSS 6.2%CVE-2022-29404Denial of service in mod_lua r:parsebodyEPSS 6.2%CVE-2021-23926XMLBeans XML Entity ExpansionEPSS 6.2%CVE-2017-15702In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of whiEPSS 6.2%CVE-2019-0223While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and itEPSS 6.2%CVE-2026-33453CRITICALApache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code ExecutionEPSS 6.2%CVE-2020-1946Apache SpamAssassin has an OS Command Injection vulnerabilityEPSS 6.1%CVE-2016-6810In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based admiEPSS 6.1%CVE-2017-15706As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7EPSS 6.1%CVE-2023-41080Apache Tomcat: Open redirect with FORM authenticationEPSS 6.0%CVE-2017-9801When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitraEPSS 6.0%CVE-2021-37608Arbitrary file upload vulnerability in OFBizEPSS 6.0%CVE-2021-45029Apache ShenYu 2.4.1 Groovy Code Injection & SpEL InjectionEPSS 6.0%CVE-2018-1328Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".EPSS 6.0%CVE-2024-29868CRITICALApache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token GenerationEPSS 6.0%