Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2020-11983—An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBACEPSS 1.8%CVE-2021-41971—Possible SQL Injection when template processing is enabledEPSS 1.8%CVE-2022-34321HIGHApache Pulsar: Improper Authentication for Pulsar Proxy Statistics EndpointEPSS 1.8%CVE-2022-22931—Path traversal in Apache James 3.6.1EPSS 1.8%CVE-2023-46302—Apache Submarine: Fix CVE-2022-1471 SnakeYaml unsafe deserializationEPSS 1.8%CVE-2021-34538—Apache Hive Security vulnerability in Hive with UDFsEPSS 1.8%CVE-2025-27888MEDIUMApache Druid: Server-Side Request Forgery and Cross-Site ScriptingEPSS 1.8%CVE-2018-8042—Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when thEPSS 1.8%CVE-2026-44185HIGHApache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`EPSS 1.8%CVE-2017-12613—When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and EPSS 1.7%CVE-2022-41131HIGHApache Airflow Hive Provider vulnerability (command injection via hive_cli connection)EPSS 1.7%CVE-2022-40754MEDIUMOpen RedirectEPSS 1.7%CVE-2018-1315—In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server canEPSS 1.7%CVE-2023-40611MEDIUMApache Airflow Dag Runs Broken Access Control VulnerabilityEPSS 1.7%CVE-2024-52318MEDIUMApache Tomcat: Incorrect JSP tag recycling leads to XSSEPSS 1.7%CVE-2018-8025—CVE-2018-8025 describes an issue in Apache HBase that affects the optional "Thrift 1" API server when running over HTTP. There is a race-conEPSS 1.7%CVE-2022-35724—Denial of service while reading data in Avro Rust SDKEPSS 1.7%CVE-2024-41937MEDIUMApache Airflow: Stored XSS Vulnerability on provider linkEPSS 1.7%CVE-2020-13922—Apache DolphinScheduler (incubating) Permission vulnerabilityEPSS 1.7%CVE-2024-29133MEDIUMApache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object treeEPSS 1.7%