Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-20242A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijackEPSS 5.4%CVE-2025-54920HIGHApache Spark: Spark History Server Code Execution VulnerabilityEPSS 5.3%CVE-2018-8024In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark clusterEPSS 5.3%CVE-2018-11771When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to retEPSS 5.3%CVE-2016-8750Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames pEPSS 5.2%CVE-2018-1337In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connectiEPSS 5.2%CVE-2022-30556Information Disclosure in mod_lua with websocketsEPSS 5.1%CVE-2022-25371Unauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBizEPSS 5.1%CVE-2022-25167Apache Flume vulnerable to a JNDI RCE in JMSSourceEPSS 5.1%CVE-2021-44548Apache Solr information disclosure vulnerability through DataImportHandlerEPSS 5.1%CVE-2021-26461malloc, realloc and memalign implementations are vulnerable to integer wrap-aroundsEPSS 5.0%CVE-2018-11793When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.EPSS 5.0%CVE-2017-12619Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user session. Issue was reportEPSS 4.9%CVE-2021-30245Code execution in Apache OpenOffice via non-http(s) schemes in HyperlinksEPSS 4.9%CVE-2019-10078A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to sessEPSS 4.9%CVE-2017-15707In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack usiEPSS 4.9%CVE-2018-11798The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in whiEPSS 4.9%CVE-2017-9799It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possEPSS 4.9%CVE-2022-28614read beyond bounds via ap_rwrite()EPSS 4.9%CVE-2023-23638MEDIUMApache Dubbo Deserialization Vulnerability Gadgets BypassEPSS 4.8%