Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-36372—Original block tokens are persisted and can be retrievedEPSS 2.5%CVE-2021-37147—Request Smuggling - LF line endingEPSS 2.5%CVE-2017-5661—In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciouslyEPSS 2.5%CVE-2021-32566—Specific sequence of HTTP/2 frames can cause ATS to crashEPSS 2.5%CVE-2021-38295—Privilege escalation vulnerability when using HTML attachmentsEPSS 2.5%CVE-2021-34797—Apache Geode project log file redaction of sensitive information vulnerabilityEPSS 2.5%CVE-2022-45143—Apache Tomcat: JsonErrorReportValve escapingEPSS 2.5%CVE-2017-15712—Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. TEPSS 2.5%CVE-2021-26558—Deserialization of Untrusted DataEPSS 2.5%CVE-2021-41585—ATS stops accepting connections on FreeBSDEPSS 2.5%CVE-2026-62392HIGHApache Kylin: OS Command Injection via Async Query APIEPSS 2.5%CVE-2022-25757—Apache APISIX: the body_schema check in request-validation plugin can be bypassedEPSS 2.5%CVE-2018-17186—An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, EPSS 2.5%CVE-2017-15693—In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocationEPSS 2.5%CVE-2024-28752CRITICALApache CXF SSRF Vulnerability using the Aegis databindingEPSS 2.5%CVE-2021-36161—Unprotected input value toString cause RCEEPSS 2.5%CVE-2024-22393CRITICALApache Answer: Pixel Flood Attack by uploading the large pixel fileEPSS 2.5%CVE-2020-1926—Timing attack in Cookie signature verificationEPSS 2.5%CVE-2018-11792—In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as havEPSS 2.5%CVE-2024-38474HIGHApache HTTP Server weakness with encoded question marks in backreferencesEPSS 2.5%