Vulnerabilidades em Apache Software Foundation

2.372 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-39135—Apache Calcite: potential XEE attacksEPSS 2.2%CVE-2017-3151—Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionaliEPSS 2.2%CVE-2022-25169—Apache Tika BPGParser Memory Usage DoSEPSS 2.2%CVE-2018-1319—In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL,EPSS 2.2%CVE-2023-42795MEDIUMApache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requestsEPSS 2.2%CVE-2023-28710HIGHApache Airflow Spark Provider Arbitrary File Read via JDBCEPSS 2.2%CVE-2018-1284—In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_floEPSS 2.1%CVE-2024-43202CRITICALApache DolphinScheduler: Remote Code Execution VulnerabilityEPSS 2.1%CVE-2023-40272HIGHApache Airflow Spark Provider Arbitrary File Read via JDBCEPSS 2.1%CVE-2022-38054—Session FixationEPSS 2.1%CVE-2021-37150MEDIUMProtocol vs scheme mismatchEPSS 2.1%CVE-2021-32565—HTTP Request Smuggling, content length with invalid chartersEPSS 2.1%CVE-2023-27522HIGHApache HTTP Server: mod_proxy_uwsgi HTTP response splittingEPSS 2.1%CVE-2025-23184MEDIUMApache CXF: Denial of Service vulnerability with temporary filesEPSS 2.1%CVE-2016-8751—Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store sEPSS 2.1%CVE-2016-8752—Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointiEPSS 2.1%CVE-2024-36522CRITICALApache Wicket: Remote code execution via XSLT injectionEPSS 2.1%CVE-2019-0231—Apache MINA SSLFilter security IssueEPSS 2.1%CVE-2021-40111—Apache James IMAP parsing Denial Of ServiceEPSS 2.1%CVE-2023-29215CRITICALApache Linkis JDBC EngineCon has a deserialization command executionEPSS 2.1%