Vulnerabilidades em Apache Software Foundation

2.334 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-3154—Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.EPSS 2.1%CVE-2017-3155—Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.EPSS 2.1%CVE-2021-37533MEDIUMApache Commons Net's FTP client trusts the host from PASV response by defaultEPSS 2.1%CVE-2022-29158—Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBizEPSS 2.0%CVE-2017-17835—In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.EPSS 2.0%CVE-2018-1291—Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entitEPSS 2.0%CVE-2022-31778—Transfer-Encoding not treated as hop-by-hopEPSS 2.0%CVE-2021-41766—Insecure Java Deserialization in Apache KarafEPSS 2.0%CVE-2017-12614—It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS atteEPSS 2.0%CVE-2017-15696—When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configurEPSS 2.0%CVE-2023-30631—Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't workEPSS 2.0%CVE-2016-8648HIGHIt was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via EPSS 2.0%CVE-2022-47185HIGHApache Traffic Server: Invalid Range header causes a crashEPSS 2.0%CVE-2018-8031—The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a maliciousEPSS 2.0%CVE-2023-40712—Apache Airflow: Secrets can be unmasked in the "Rendered Template" EPSS 2.0%CVE-2025-68675HIGHApache Airflow: proxy credentials for various providers might leak in task logsEPSS 2.0%CVE-2022-46751HIGHApache Ivy: XML External Entity vulnerability in Apache IvyEPSS 2.0%CVE-2023-27602CRITICALApache Linkis publicsercice module unrestricted upload of fileEPSS 2.0%CVE-2017-7683—Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.EPSS 2.0%CVE-2016-8748—In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessedEPSS 2.0%