Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-8008—Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that EPSS 2.3%CVE-2018-1298—A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocEPSS 2.3%CVE-2021-36739MEDIUMXSS vulnerability in the MVCBean JSP portlet maven archetypeEPSS 2.3%CVE-2021-36737—XSS in V3 Demo PortletEPSS 2.3%CVE-2021-36738—XSS vulnerability in the JSP version of the Apache Pluto Applicant MVCBean CDI portletEPSS 2.3%CVE-2022-28129—Insufficient Validation of HTTP/1.x HeadersEPSS 2.3%CVE-2024-23672MEDIUMApache Tomcat: WebSocket DoS with incomplete closing handshakeEPSS 2.3%CVE-2024-52338CRITICALApache Arrow R package: Arbitrary code execution when loading a malicious data fileEPSS 2.3%CVE-2018-11777—In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if rangerEPSS 2.3%CVE-2023-49109CRITICALRemote Code Execution in Apache DolphinschedulerEPSS 2.3%CVE-2023-49898—Apache StreamPark (incubating): Authenticated system users could trigger remote command executionEPSS 2.3%CVE-2022-31780—HTTP/2 framing vulnerabilitiesEPSS 2.3%CVE-2015-5241—After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users toEPSS 2.3%CVE-2018-8017—In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.EPSS 2.3%CVE-2023-39553HIGHApache Airflow Drill Provider Arbitrary File Read VulnerabilityEPSS 2.3%CVE-2021-31164—Apache Unomi log injectionEPSS 2.3%CVE-2022-24289—Deserialization of untrusted data in the Hessian Component of Apache Cayenne 4.1 with older Java versionsEPSS 2.3%CVE-2023-25754CRITICALApache Airflow: Privilege escalation using airflow logsEPSS 2.3%CVE-2018-8016—The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, whichEPSS 2.3%CVE-2025-48924MEDIUMApache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputsEPSS 2.3%