Vulnerabilidades em Apache Software Foundation

2.345 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-27578—Cross Site Scripting in markdown interpreterEPSS 3.2%CVE-2012-3353—The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files iEPSS 3.2%CVE-2022-46421CRITICALApache Airflow Hive Provider: Hive Provider RCE vulnerability with hive_cli_paramsEPSS 3.2%CVE-2018-1290—In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuousEPSS 3.2%CVE-2022-36364—Apache Calcite Avatica JDBC driver `httpclient_impl` connection property can be used as an RCE vectorEPSS 3.2%CVE-2016-8738—In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is posEPSS 3.2%CVE-2017-15699—A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remoteEPSS 3.2%CVE-2020-17528—Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent lengthEPSS 3.2%CVE-2024-38477HIGHApache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious requestEPSS 3.2%CVE-2018-8023—Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions EPSS 3.2%CVE-2024-23946MEDIUMApache OFBiz: Path traversal or file inclusionEPSS 3.1%CVE-2024-52577CRITICALApache Ignite: Possible RCE when deserializing incoming messages by the server nodeEPSS 3.1%CVE-2024-56512LOWApache NiFi: Missing Complete Authorization for Parameter and Service ReferencesEPSS 3.1%CVE-2017-3161—The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.EPSS 3.1%CVE-2018-1310—Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActEPSS 3.1%CVE-2018-17188—Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulEPSS 3.1%CVE-2021-31812—A carefully crafted PDF file can trigger an infinite loop while loading the fileEPSS 3.1%CVE-2017-7665—In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms oEPSS 3.1%CVE-2021-41561—Apache Parquet-MR potential DoS in case of malicious Parquet fileEPSS 3.1%CVE-2016-6800—The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are relEPSS 3.1%