Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-30188HIGHApache DolphinScheduler: Resource File Read And Write VulnerabilityEPSS 6.0%CVE-2024-27135HIGHApache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code ExecutionEPSS 6.0%CVE-2018-17197A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.EPSS 5.9%CVE-2017-5643Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.EPSS 5.9%CVE-2023-45648MEDIUMApache Tomcat: Trailer header parsing too lenientEPSS 5.8%CVE-2022-22728libapreq2 multipart form parse memory corruptionEPSS 5.8%CVE-2015-2992Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.EPSS 5.8%CVE-2019-10095bash command injection in spark interpreterEPSS 5.7%CVE-2020-13959Velocity Tools XSS VulnerabilityEPSS 5.7%CVE-2018-11804Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. EPSS 5.7%CVE-2021-40146A Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.javaEPSS 5.7%CVE-2020-11995Apache Dubbo default deserialization protocol Hessian2 cause CREEPSS 5.7%CVE-2017-7660Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially craEPSS 5.6%CVE-2016-6813Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious EPSS 5.6%CVE-2018-8027Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.EPSS 5.5%CVE-2023-34396MEDIUMApache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart formsEPSS 5.5%CVE-2018-1282This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cEPSS 5.5%CVE-2021-35936No Authentication on Logging ServerEPSS 5.5%CVE-2018-11762In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and tEPSS 5.4%CVE-2023-34149MEDIUMApache Struts: DoS via OOM owing to not properly checking of list boundsEPSS 5.4%