Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2021-41571—Pulsar Admin API allows access to data from other tenants using getMessageById APIEPSS 1.7%CVE-2024-39877HIGHApache Airflow: DAG Author Code Execution possibility in airflow-schedulerEPSS 1.7%CVE-2024-31865MEDIUMApache Zeppelin: Cron arbitrary user impersonation with improper privilegesEPSS 1.7%CVE-2026-66713CRITICALApache Axis2/Java: deserialization of untrusted DataEPSS 1.7%CVE-2024-36387MEDIUMApache HTTP Server: DoS by Null pointer in websocket over HTTP/2EPSS 1.7%CVE-2023-44981CRITICALApache ZooKeeper: Authorization bypass in SASL Quorum Peer AuthenticationEPSS 1.7%CVE-2022-35278—HTML Injection in ActiveMQ Artemis Web ConsoleEPSS 1.7%CVE-2021-45230—Apache Airflow: Creating DagRuns didn't respect Dag-level permissions in the WebserverEPSS 1.7%CVE-2025-32897CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 1.7%CVE-2023-34434HIGHApache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath paramEPSS 1.7%CVE-2021-44145—Apache NiFi information disclosure by XXEEPSS 1.7%CVE-2024-28098MEDIUMApache Pulsar: Improper Authorization For Topic-Level Policy ManagementEPSS 1.7%CVE-2024-23952MEDIUMApache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)EPSS 1.7%CVE-2022-29405—Apache Archiva Arbitrary user password reset vulnerabilityEPSS 1.7%CVE-2024-38286HIGHApache Tomcat: Denial of ServiceEPSS 1.7%CVE-2024-45034HIGHApache Airflow: Authenticated DAG authors could execute code on scheduler nodesEPSS 1.7%CVE-2021-39232—Missing admin check for SCM related admin commandsEPSS 1.7%CVE-2026-41293CRITICALApache Tomcat: HTTP/2 request headers not validatedEPSS 1.7%CVE-2022-32287HIGHApache UIMA prior to 3.3.1 has a path traversal vulnerability when extracting (PEAR) archivesEPSS 1.7%CVE-2018-1307—In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediatesEPSS 1.7%