Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-7687—When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1EPSS 2.4%CVE-2021-32567—Reading HTTP/2 frames too many timesEPSS 2.4%CVE-2017-9790—When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3EPSS 2.4%CVE-2022-41704HIGHApache Batik prior to 1.16 allows RCE when loading untrusted SVG inputEPSS 2.4%CVE-2026-40047CRITICALApache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducerEPSS 2.4%CVE-2016-6807—Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operatiEPSS 2.4%CVE-2022-38648—PDFTranscoder does not block external resourcesEPSS 2.4%CVE-2021-43082—heap-buffer-overflow with stats-over-http pluginEPSS 2.4%CVE-2022-40145CRITICALApache Karaf: JDBC JAAS LDAP injectionEPSS 2.4%CVE-2021-43410—airavata-django-portal allows CRLF log injection because of the lack of escaping in the log statementsEPSS 2.4%CVE-2021-41532—Unauthenticated access to Ozone Recon HTTP endpointsEPSS 2.4%CVE-2022-32549—log injection in Sling loggingEPSS 2.4%CVE-2022-45378CRITICALApache SOAP allows unauthenticated users to potentially invoke arbitrary codeEPSS 2.4%CVE-2021-45457—Overly broad CORS configurationEPSS 2.4%CVE-2021-39233—Container-related datanode operations can be called without authorizationEPSS 2.4%CVE-2021-39231—Missing authentication/authorization on internal RPC endpointsEPSS 2.4%CVE-2022-31779—Improper HTTP/2 scheme and method validationEPSS 2.4%CVE-2023-34212—Apache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS ComponentsEPSS 2.4%CVE-2021-38542—Apache James vulnerable to STARTTLS command injection (IMAP and POP3)EPSS 2.3%CVE-2017-7664—Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.EPSS 2.3%