Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-45910MEDIUMApache ManifoldCF: LDAP Injection Vulnerability - ActiveDirectory AuthoritiesEPSS 1.5%CVE-2022-36125HIGHInteger overflow when reading corrupted .avro file in Avro Rust SDKEPSS 1.5%CVE-2024-23945MEDIUMApache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification failsEPSS 1.5%CVE-2022-34662MEDIUMApache DolphinScheduler prior to 3.0.0 allows path traversalEPSS 1.5%CVE-2021-41831—Timestamp Manipulation with Signature WrappingEPSS 1.5%CVE-2023-25956HIGHApache Airflow AWS Provider: Arbitrary file read via AWS providerEPSS 1.5%CVE-2021-41972—Credentials leakEPSS 1.5%CVE-2023-47037—Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)EPSS 1.5%CVE-2023-46750MEDIUMApache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.EPSS 1.5%CVE-2023-33933HIGHApache Traffic Server: s3_auth plugin problem with hash calculationEPSS 1.5%CVE-2022-47184HIGHApache Traffic Server: The TRACE method can be use to disclose network informationEPSS 1.5%CVE-2025-46762HIGHApache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadataEPSS 1.5%CVE-2024-23539HIGHApache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.EPSS 1.5%CVE-2022-26850—Insufficiently protected credentialsEPSS 1.5%CVE-2023-25613—LDAP Injection Vulnerability in Apache KerbyEPSS 1.5%CVE-2022-34917HIGHUnauthenticated clients may cause OutOfMemoryError on Apache Kafka BrokersEPSS 1.5%CVE-2023-34150MEDIUMApache Any23: Possible excessive allocation of resources reading input.EPSS 1.5%CVE-2018-11799—Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML thEPSS 1.5%CVE-2023-39913HIGHApache UIMA Java SDK Core, Apache UIMA Java SDK CPE, Apache UIMA Java SDK Vinci adapter, Apache UIMA Java SDK tools: Potential untrusted code execution when deserializing certain binary CAS formatsEPSS 1.5%CVE-2024-23807HIGHApache Xerces C++: Use-after-free on external DTD scanEPSS 1.5%