Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-22849MEDIUMApache Sling App CMS: XSS in CMS Reference / UI ComponentsEPSS 1.4%CVE-2023-33008MEDIUMApache Johnzon: Prevent inefficient internal conversion from BigDecimal at large scaleEPSS 1.4%CVE-2022-24280MEDIUMApache Pulsar Proxy target broker address isn't validatedEPSS 1.4%CVE-2022-36124HIGHMemory overconsumption in Avro Rust SDKEPSS 1.4%CVE-2023-42792—Apache Airflow: Improper access control to DAG resourcesEPSS 1.4%CVE-2023-34340CRITICALApache Accumulo: Accumulo 2.1.0 may incorrectly validate cached credentialsEPSS 1.4%CVE-2017-7667—Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same oriEPSS 1.4%CVE-2017-12625—Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be definedEPSS 1.4%CVE-2023-49299HIGHApache DolphinScheduler: Arbitrary js execute as root for authenticated usersEPSS 1.4%CVE-2022-43766HIGHApache IoTDB prior to 0.13.3 allows DoSEPSS 1.4%CVE-2023-26268MEDIUMApache CouchDB, IBM Cloudant: Information sharing via couchjs processesEPSS 1.4%CVE-2024-31866CRITICALApache Zeppelin: Interpreter download command does not escape malicious code injectionEPSS 1.4%CVE-2025-58098HIGHApache HTTP Server: Server Side Includes adds query string to #exec cmd=...EPSS 1.4%CVE-2009-4267—The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the EPSS 1.4%CVE-2022-34271HIGHApache Atlas: zip path traversal in import functionalityEPSS 1.4%CVE-2022-46337CRITICALApache Derby: LDAP injection vulnerability in authenticatorEPSS 1.4%CVE-2022-25147—Apache Portable Runtime Utility (APR-util): out-of-bounds writes in the apr_base64 family of functionsEPSS 1.4%CVE-2023-46288—Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is setEPSS 1.4%CVE-2023-22888—Apache Airflow: Scheduler remote DoSEPSS 1.4%CVE-2021-39234—Raw block data can be read bypassing ACL/authorizationEPSS 1.4%