Vulnerabilidades em Apache Software Foundation

2.334 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2024-40725MEDIUMApache HTTP Server: source code disclosure with handlers configured via AddTypeEPSS 4.2%CVE-2018-17198Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies EPSS 4.1%CVE-2017-5662In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send malicioEPSS 4.1%CVE-2021-37578Remote code execution via RMIEPSS 4.1%CVE-2022-40189CRITICALApache Airlfow Pig Provider RCEEPSS 4.1%CVE-2026-50229MEDIUMApache Tomcat: XSS in number guess exampleEPSS 4.1%CVE-2021-30179Apache Dubbo Pre-auth RCE via Java deserialization in the Generic filterEPSS 4.1%CVE-2018-8019When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This alloEPSS 4.1%CVE-2025-31651CRITICALApache Tomcat: Bypass of rules in Rewrite ValveEPSS 4.0%CVE-2020-13924In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directEPSS 4.0%CVE-2021-33191MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocolEPSS 4.0%CVE-2018-11778UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions pEPSS 4.0%CVE-2020-9494Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cEPSS 4.0%CVE-2022-32533CRITICALApache Portals Jetspeed XSS, CSRF, SSRF, and XXE issuesEPSS 4.0%CVE-2020-1928An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugginEPSS 4.0%CVE-2018-8030A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to puEPSS 3.9%CVE-2021-26118Flaw in ActiveMQ Artemis OpenWire supportEPSS 3.9%CVE-2018-8010This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solEPSS 3.9%CVE-2023-38709HIGHApache HTTP Server: HTTP response splittingEPSS 3.9%CVE-2021-33036Apache Hadoop Privilege escalation vulnerabilityEPSS 3.9%