Vulnerabilidades em Apache Software Foundation

2.344 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-27906—A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the fileEPSS 3.3%CVE-2018-1296—In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during liEPSS 3.3%CVE-2021-28131—Impala logs contain secretsEPSS 3.3%CVE-2024-38346CRITICALApache CloudStack: Unauthenticated cluster service port leads to remote executionEPSS 3.3%CVE-2021-33580—regex injection leading to DoSEPSS 3.3%CVE-2018-1290—In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuousEPSS 3.3%CVE-2017-15714—The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing tEPSS 3.3%CVE-2017-5635—In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the oEPSS 3.3%CVE-2024-22399CRITICALApache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata ServerEPSS 3.3%CVE-2023-40743CRITICALApache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getServiceEPSS 3.3%CVE-2026-35152HIGHApache Fineract: SQL injection in runreports endpointEPSS 3.3%CVE-2023-50291HIGHApache Solr: System Property redaction logic inconsistency can lead to leaked passwordsEPSS 3.3%CVE-2016-8738—In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is posEPSS 3.3%CVE-2020-13929—Notebook permissions bypassEPSS 3.3%CVE-2024-47561CRITICALApache Avro Java SDK: Arbitrary Code Execution when reading Avro schema (Java SDK)EPSS 3.3%CVE-2021-36163—Unsafe deserialization in providers using the Hessian protocolEPSS 3.3%CVE-2019-12408—It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had EPSS 3.3%CVE-2018-11766—In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbEPSS 3.2%CVE-2020-17532—Apache ServiceComb Yaml remote deserialization vulnerabilityEPSS 3.2%CVE-2023-37895CRITICALApache Jackrabbit RMI access can lead to RCEEPSS 3.2%