Vulnerabilidades em Apache Software Foundation

2.371 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-26697Apache Airflow: Lineage API endpoint for Experimental API missed authentication checkEPSS 4.6%CVE-2018-1309Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code executiEPSS 4.5%CVE-2020-1940The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitEPSS 4.5%CVE-2017-17837The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off aftEPSS 4.5%CVE-2021-21501ServiceComb ServiceCenter Directory TraversalEPSS 4.4%CVE-2024-39887MEDIUMApache Superset: Improper SQL authorisation, parse not checking for specific engine functionsEPSS 4.4%CVE-2018-1331In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a securEPSS 4.4%CVE-2022-29599Commandline class shell injection vulnerabilitiesEPSS 4.4%CVE-2017-15701In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frameEPSS 4.4%CVE-2020-17513In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.EPSS 4.4%CVE-2021-23901An XML external entity (XXE) injection vulnerability exists in the Nutch DmozParserEPSS 4.4%CVE-2021-39239XML External Entity (XXE) vulnerabilityEPSS 4.3%CVE-2022-23223Apache ShenYu Password leakageEPSS 4.3%CVE-2021-23937DNS proxy and possible amplification attackEPSS 4.3%CVE-2018-8003Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP reqEPSS 4.2%CVE-2022-26612Arbitrary file write in FileUtil#unpackEntries on WindowsEPSS 4.2%CVE-2018-8020Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lisEPSS 4.2%CVE-2017-7676Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can reEPSS 4.2%CVE-2022-25168Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTarEPSS 4.2%CVE-2017-9795When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster mEPSS 4.2%