Vulnerabilidades em Apache Software Foundation

2.334 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-3161The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.EPSS 3.9%CVE-2021-40439Billion LaughsEPSS 3.9%CVE-2016-8744Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should EPSS 3.8%CVE-2022-45047CRITICALApache MINA SSHD: Java unsafe deserialization vulnerabilityEPSS 3.8%CVE-2019-0200A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticatEPSS 3.8%CVE-2016-4462By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template EnginEPSS 3.8%CVE-2010-2232In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.EPSS 3.8%CVE-2016-15057CRITICALApache Continuum: Command injection leading to RCEEPSS 3.8%CVE-2022-23945Apache ShenYu missing authentication allows gateway registrationEPSS 3.8%CVE-2017-3160After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetchEPSS 3.8%CVE-2022-28330read beyond bounds in mod_isapiEPSS 3.7%CVE-2022-33140Improper Neutralization of Command Elements in Shell User Group ProviderEPSS 3.7%CVE-2021-40525Sieve file storage vulnerable to path traversal attacksEPSS 3.7%CVE-2017-12624Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attaEPSS 3.7%CVE-2018-1330When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing EPSS 3.7%CVE-2016-6798In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the inpEPSS 3.7%CVE-2018-1324A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFEPSS 3.7%CVE-2020-17533Apache Accumulo Improper Handling of Insufficient PermissionsEPSS 3.7%CVE-2016-3086The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by EPSS 3.6%CVE-2017-5636In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to anEPSS 3.6%