Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-1339—A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.EPSS 2.6%CVE-2017-15695—When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to dEPSS 2.6%CVE-2016-5394—In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictivEPSS 2.6%CVE-2021-45229—Apache Airflow: Reflected XSS via Origin Query Argument in URLEPSS 2.6%CVE-2022-29265—Improper Restriction of XML External Entity References in Multiple ComponentsEPSS 2.6%CVE-2021-37149—Request Smuggling - multiple attacksEPSS 2.6%CVE-2021-37148—Request Smuggling - transfer encoding validationEPSS 2.6%CVE-2017-12607—A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documenEPSS 2.6%CVE-2021-39236—Owners of the S3 tokens are not validatedEPSS 2.6%CVE-2016-6799—Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v()EPSS 2.6%CVE-2022-37021—Apache Geode deserialization of untrusted data flaw when using JMX over RMI on Java 8.EPSS 2.6%CVE-2021-42357—DOM based XSS Vulnerability in Apache KnoxEPSS 2.6%CVE-2018-1289—In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to queEPSS 2.6%CVE-2018-11787—In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/consoEPSS 2.6%CVE-2022-38398—Server-Side Request Forgery Information Disclosure VulnerabilityEPSS 2.6%CVE-2021-27738—Improper Access Control to Streaming Coordinator & SSRFEPSS 2.6%CVE-2022-45875CRITICALApache DolphinScheduler: Remote command execution Vulnerability in script alert pluginEPSS 2.5%CVE-2018-17187—The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. UnEPSS 2.5%CVE-2021-36373—Apache Ant TAR archive denial of service vulnerabilityEPSS 2.5%CVE-2017-15720—In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.EPSS 2.5%