Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2023-22832HIGHApache NiFi: Improper Restriction of XML External Entity References in ExtractCCDAAttributesEPSS 1.4%CVE-2026-41606MEDIUMApache Thrift: c_glib dispatch stack overflowEPSS 1.4%CVE-2025-27553HIGHApache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENTEPSS 1.4%CVE-2026-67260HIGHApache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserializationEPSS 1.4%CVE-2025-64405HIGHApache OpenOffice: Remote documents loaded without prompt via DDE functionEPSS 1.4%CVE-2023-50783—Apache Airflow: Improper access control vulnerability on the "varimport" endpointEPSS 1.4%CVE-2021-41830—Double Certificate AttackEPSS 1.4%CVE-2022-45347CRITICALApache ShardingSphere-Proxy: MySQL authentication bypassEPSS 1.4%CVE-2024-23320HIGHApache DolphinScheduler: Arbitrary js execution as root for authenticated usersEPSS 1.4%CVE-2024-31860MEDIUMApache Zeppelin: Path traversal vulnerabilityEPSS 1.4%CVE-2023-25695MEDIUMInformation disclosure in Apache AirflowEPSS 1.4%CVE-2022-46769MEDIUMApache Sling App CMS: XSS in CMS Site Group DetailEPSS 1.4%CVE-2026-41602HIGHApache Thrift: Go TFramedTransport uint32 overflowEPSS 1.4%CVE-2022-40954MEDIUMApache Airflow Spark Provider RCE that bypass restrictions to read arbitrary filesEPSS 1.4%CVE-2021-37839—Improper access to dataset metadata informationEPSS 1.4%CVE-2024-31862MEDIUMApache Zeppelin: Denial of service with invalid notebook nameEPSS 1.4%CVE-2024-29834MEDIUMApache Pulsar: Improper Authorization For Namespace and Topic Management EndpointsEPSS 1.4%CVE-2017-9797—When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode aEPSS 1.4%CVE-2023-31066CRITICALApache InLong: Insecure direct object references for inlong sourcesEPSS 1.4%CVE-2020-1932—An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are ablEPSS 1.4%