Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2017-12631—Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request ForEPSS 1.6%CVE-2023-52291HIGHApache StreamPark (incubating): Unchecked maven build params could trigger remote command executionEPSS 1.6%CVE-2022-26112CRITICALPinot query endpoint and the realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function supportEPSS 1.6%CVE-2026-47323CRITICALApache Camel: Camel-CXF Message Header Injection via Missing Inbound FilteringEPSS 1.6%CVE-2024-47208CRITICALApache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCEEPSS 1.6%CVE-2023-25691CRITICALApache Airflow Google Provider: Google Cloud Sql Provider Remote Command ExecutionEPSS 1.6%CVE-2023-31038HIGHApache Log4cxx: SQL injection when using ODBC appenderEPSS 1.6%CVE-2022-43985MEDIUMApache Airflow prior to 2.4.2 has an open redirectEPSS 1.6%CVE-2023-41081HIGHApache Tomcat Connectors: Unexpected use of first declared worker in mod_jk for unmapped requestEPSS 1.6%CVE-2023-37415HIGHApache Airflow Apache Hive Provider: Improper Input Validation in Hive Provider with proxy_userEPSS 1.6%CVE-2022-26884MEDIUMApache DolphinScheduler exposes files without authenticationEPSS 1.6%CVE-2024-34693MEDIUMApache Superset: Server arbitrary file readEPSS 1.6%CVE-2022-31777MEDIUMApache Spark XSS vulnerability in log viewer UI JavascriptEPSS 1.6%CVE-2017-9792—In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table daEPSS 1.6%CVE-2021-44759—Improper authentication vulnerability in TLS origin verificationEPSS 1.6%CVE-2022-28331CRITICALApache Portable Runtime (APR): Windows out-of-bounds write in apr_socket_sendv functionEPSS 1.6%CVE-2026-29169HIGHApache HTTP Server: mod_dav_lock indirect lock crashEPSS 1.6%CVE-2024-32077MEDIUMApache Airflow: XSS vulnerability in Task Instance Log/Log DetailsEPSS 1.6%CVE-2024-50306CRITICALApache Traffic Server: Server process can fail to drop privilegeEPSS 1.6%CVE-2023-36543—Apache Airflow: ReDoS via dags functionEPSS 1.6%