Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-8016—The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, whichEPSS 2.3%CVE-2025-48924MEDIUMApache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputsEPSS 2.3%CVE-2020-17517—Ozone S3 Gateway allows bucket and key access to non authenticated usersEPSS 2.3%CVE-2021-36162—Unprotected yaml deserialization cause RCEEPSS 2.3%CVE-2022-24948—Apache JSPWiki Cross-site scripting vulnerability on User Preferences screenEPSS 2.3%CVE-2023-38435—Apache Felix Healthcheck Webconsole Plugin: XSS in healthcheck webconsole pluginEPSS 2.2%CVE-2021-25642—Apache Hadoop YARN remote code execution in ZKConfigurationStore of capacity schedulerEPSS 2.2%CVE-2022-46364CRITICALApache CXF SSRF VulnerabilityEPSS 2.2%CVE-2017-3165—In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to ruEPSS 2.2%CVE-2021-44791—Reflected XSS on certain HTTP endpointsEPSS 2.2%CVE-2017-3153—Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.EPSS 2.2%CVE-2017-3152—Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.EPSS 2.2%CVE-2017-3150—Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.EPSS 2.2%CVE-2024-45505HIGHApache HertzBeat: Exists Native Deser RCE and file writing vulnerabilitiesEPSS 2.2%CVE-2017-15713—Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to exEPSS 2.2%CVE-2022-26477—Denial of service in readExternal methodEPSS 2.2%CVE-2017-9803—Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-EPSS 2.2%CVE-2017-5654—In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to EPSS 2.2%CVE-2017-7671—There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This isEPSS 2.2%CVE-2022-47937CRITICALMultiple parsing problems in the Apache Sling Commons JSON moduleEPSS 2.2%