Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2016-8746—Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recuEPSS 2.7%CVE-2023-47804—Apache OpenOffice: Macro URL arbitrary script executionEPSS 2.7%CVE-2021-35474—Dynamic stack buffer overflow in cachekey pluginEPSS 2.7%CVE-2019-0187—Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connecEPSS 2.7%CVE-2022-40955HIGHDeserialization attack in Apache InLong prior to version 1.3.0 allows RCE via JDBCEPSS 2.7%CVE-2021-33190—Bypass network access controlEPSS 2.7%CVE-2018-17192—The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some broEPSS 2.7%CVE-2022-40664CRITICALAuthentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcherEPSS 2.7%CVE-2017-7663—Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.EPSS 2.7%CVE-2023-46589HIGHApache Tomcat: HTTP request smuggling via malformed trailer headersEPSS 2.7%CVE-2021-36374—Apache Ant ZIP, and ZIP based, archive denial of service vulerabilityEPSS 2.6%CVE-2022-42890—Apache Batik prior to 1.16 allows RCE via scriptingEPSS 2.6%CVE-2022-25370—Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBizEPSS 2.6%CVE-2023-39508HIGHApache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledgesEPSS 2.6%CVE-2022-28890—Processing external DTDsEPSS 2.6%CVE-2022-39198CRITICALApache Dubbo Hession Deserialization Vulnerability Gadgets BypassEPSS 2.6%CVE-2022-26650—Apache ShenYu (incubating) Regular expression denial of serviceEPSS 2.6%CVE-2020-17511—In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in AirEPSS 2.6%CVE-2017-7677—In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission EPSS 2.6%CVE-2022-30126—Apache Tika Regular Expression Denial of Service in Standards ExtractorEPSS 2.6%