Vulnerabilidades em Apache Software Foundation

2.370 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-45802—Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RSTEPSS 3.0%CVE-2023-50292HIGHApache Solr: Solr Schema Designer blindly "trusts" all configsets, possibly leading to RCE by unauthenticated usersEPSS 3.0%CVE-2014-0043—In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of partiEPSS 3.0%CVE-2016-6804—The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operatiEPSS 3.0%CVE-2022-42920—Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writingEPSS 3.0%CVE-2023-31122—Apache HTTP Server: mod_macro buffer over-readEPSS 3.0%CVE-2018-1299—In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers usEPSS 3.0%CVE-2021-27807—A carefully crafted PDF file can trigger an infinite loop while loading the fileEPSS 3.0%CVE-2022-44621CRITICALApache Kylin: Command injection by Diagnosis ControllerEPSS 3.0%CVE-2017-12610—In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protEPSS 3.0%CVE-2018-11758—This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI toEPSS 3.0%CVE-2017-7688—Apache OpenMeetings 1.0.0 updates user password in insecure manner.EPSS 3.0%CVE-2018-17194—When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On EPSS 3.0%CVE-2017-7686—Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional funcEPSS 3.0%CVE-2019-12397—Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later versionEPSS 3.0%CVE-2021-43045—Possible DOS vulnerabilities in C# Avro SDKEPSS 3.0%CVE-2017-5659—Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.EPSS 3.0%CVE-2022-42468CRITICALApache Flume prior to 1.11.0 has an Improper Input Validation (JNDI Injection) in JMSSourceEPSS 2.9%CVE-2025-46701HIGHApache Tomcat: Security constraint bypass for CGI scriptsEPSS 2.9%CVE-2021-37404—Heap buffer overflow in libhdfs native libraryEPSS 2.9%