Vulnerabilidades em Apache Software Foundation

2.371 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-15717—A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilEPSS 2.9%CVE-2021-31522—Apache Kylin unsafe class loadingEPSS 2.9%CVE-2022-27479—SQL injection vulnerability in chart data APIEPSS 2.9%CVE-2026-44825HIGHApache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure usersEPSS 2.9%CVE-2020-17529—Apache NuttX (incubating) Out of Bound Write from invalid fragmentation offset value specified in the IP headerEPSS 2.9%CVE-2017-12608—A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craEPSS 2.9%CVE-2021-26296—Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFacesEPSS 2.9%CVE-2021-33192—Display information UI XSSEPSS 2.9%CVE-2016-5396—Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.EPSS 2.9%CVE-2022-34916—Improper Input Validation (JNDI Injection) in JMSMessageConsumerEPSS 2.9%CVE-2024-24795MEDIUMApache HTTP Server: HTTP Response Splitting in multiple modulesEPSS 2.9%CVE-2023-28935HIGHApache UIMA DUCC: DUCC (EOL) allows RCEEPSS 2.9%CVE-2020-1936—Stored XSS in Apache AmbariEPSS 2.9%CVE-2026-55957HIGHApache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bindEPSS 2.9%CVE-2017-7685—Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.EPSS 2.9%CVE-2021-40110—Apache James IMAP vulnerable to a ReDoSEPSS 2.9%CVE-2022-25312—An XML external entity (XXE) injection vulnerability exists in the Apache Any23 RDFa XSLTStylesheet extractorEPSS 2.9%CVE-2017-5640—It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemoEPSS 2.9%CVE-2022-26779—Apache Cloudstack insecure random number generation affects project email invitationEPSS 2.9%CVE-2017-12632—A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host heaEPSS 2.8%