Vulnerabilidades em Apache Software Foundation

2.345 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2018-11786—In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any useEPSS 1.9%CVE-2023-36542HIGHApache NiFi: Potential Code Injection with Properties Referencing Remote ResourcesEPSS 1.9%CVE-2024-27894HIGHApache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS ProxyingEPSS 1.9%CVE-2023-25693CRITICALSqoop Apache Airflow Provider Remote Code Execution VulnerabilityEPSS 1.9%CVE-2017-5642—During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.EPSS 1.9%CVE-2021-43980LOWApache Tomcat: Information disclosureEPSS 1.9%CVE-2022-39944HIGHThe Apache Linkis JDBC EngineConn module has a RCE VulnerabilityEPSS 1.9%CVE-2022-37865CRITICALApache Ivy allows creating/overwriting any file on the systemEPSS 1.9%CVE-2022-36760CRITICALApache HTTP Server: mod_proxy_ajp Possible request smugglingEPSS 1.9%CVE-2018-11783—sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin.EPSS 1.9%CVE-2017-15700—A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, thEPSS 1.9%CVE-2023-40195HIGHApache Airflow Spark Provider Deserialization Vulnerability RCEEPSS 1.9%CVE-2022-38362—Docker Provider <3.0 RCE vulnerability in example dagEPSS 1.9%CVE-2024-26280MEDIUMApache Airflow: Overly broad default permissions for Viewer/Ops (audit logs)EPSS 1.9%CVE-2023-42794—Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on WindowsEPSS 1.9%CVE-2021-38296—Apache Spark Key Negotiation VulnerabilityEPSS 1.8%CVE-2023-40273HIGHSession fixation in Apache Airflow web interfaceEPSS 1.8%CVE-2023-28708MEDIUMApache Tomcat: JSESSIONID Cookie missing secure attribute in some configurationsEPSS 1.8%CVE-2022-24294—ReDoS in Apache MXNet RTC ModuleEPSS 1.8%CVE-2023-25692HIGHApache Airflow Google Provider: Google Cloud Sql Provider Denial Of ServiceEPSS 1.8%