Vulnerabilidades em Apache Software Foundation

2.371 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-27576—Apache OpenMeetings: bandwidth can be overloaded with public web serviceEPSS 2.8%CVE-2022-22932—Path traversal flawsEPSS 2.8%CVE-2020-1925—Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends aEPSS 2.8%CVE-2022-45462CRITICALApache DolphinScheduler prior to 2.0.5 have command execution vulnerabilityEPSS 2.8%CVE-2021-42009—Apache Traffic Control Traffic Ops Email Injection VulnerabilityEPSS 2.8%CVE-2021-26544—Apache Livy (Incubating) is vulnerable to cross site scriptingEPSS 2.8%CVE-2020-1933—A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware autEPSS 2.8%CVE-2017-7684—Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple laEPSS 2.8%CVE-2024-55633HIGHApache Superset: SQLLab Improper readonly query validation allows unauthorized write accessEPSS 2.8%CVE-2021-26559—CWE-284 Improper Access Control on Configurations Endpoint for the Stable APIEPSS 2.8%CVE-2023-35797CRITICALApache Airflow Hive Provider Beeline RCE with PrincipalEPSS 2.8%CVE-2021-28544—Apache Subversion SVN authz protected copyfrom paths regressionEPSS 2.8%CVE-2017-5649—Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users wEPSS 2.8%CVE-2018-1294—If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and thatEPSS 2.8%CVE-2023-28706CRITICALApache Airflow Hive Provider Beeline Remote Command ExecutionEPSS 2.8%CVE-2020-9485—An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "clEPSS 2.8%CVE-2018-17193—The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected EPSS 2.8%CVE-2021-28657—Infinite loop in Apache Tika's MP3 parserEPSS 2.8%CVE-2021-38555—An XML external entity (XXE) injection vulnerability exists in Apache Any23 StreamUtils.javaEPSS 2.8%CVE-2022-23913—Apache ActiveMQ Artemis DoSEPSS 2.7%