Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-50298HIGHApache Solr: Solr can expose ZooKeeper credentials via Streaming ExpressionsEPSS 1.6%CVE-2023-33934CRITICALApache Traffic Server: Differential fuzzing for HTTP request parsing discrepanciesEPSS 1.6%CVE-2021-42010CRITICALCRLF log injectionEPSS 1.6%CVE-2023-22602—Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP requestEPSS 1.6%CVE-2023-42663—Apache Airflow: Bypass permission verification to view task instances of other dagsEPSS 1.6%CVE-2021-39235—Access mode of block tokens are not enforcedEPSS 1.6%CVE-2023-33234HIGHApache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configurationEPSS 1.5%CVE-2022-42252HIGHApache Tomcat request smuggling via malformed content-lengthEPSS 1.5%CVE-2024-32838CRITICALApache Fineract: SQL injection vulnerabilities in offices API endpointEPSS 1.5%CVE-2021-28655MEDIUMApache Zeppelin: Arbitrary file deletion vulnerabilityEPSS 1.5%CVE-2024-40898CRITICALApache HTTP Server: SSRF with mod_rewrite in server/vhost context on WindowsEPSS 1.5%CVE-2026-40860CRITICALApache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqpEPSS 1.5%CVE-2023-35005—Apache Airflow: Information disclosure on configuration viewEPSS 1.5%CVE-2022-43982MEDIUMApache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URLEPSS 1.5%CVE-2023-31039CRITICALApache bRPC: ServerOptions.pid_file may cause arbitrary code executionEPSS 1.5%CVE-2025-64775HIGHApache Struts: File leak in multipart request processing causes disk exhaustion (DoS)EPSS 1.5%CVE-2022-26336—A carefully crafted TNEF file can cause an out of memory exceptionEPSS 1.5%CVE-2023-22886HIGHApache Airflow JDBC Provider: RCE VulnerabilityEPSS 1.5%CVE-2024-53299MEDIUMApache Wicket: An attacker can intentionally trigger a memory leakEPSS 1.5%CVE-2026-41042CRITICALApache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameterEPSS 1.5%