Vulnerabilidades em Apache Software Foundation

2.378 resultados
Análise Vexday

O portfólio da Apache Software Foundation acumula 1.872 CVEs catalogadas, das quais 215 são de severidade crítica e 83 contam com prova de conceito pública — fatores que ampliam a superfície de risco operacional para equipes de segurança. A taxa de exploração ativa é especialmente preocupante: 28 vulnerabilidades constam no catálogo KEV da CISA, representando uma proporção 3,3 vezes acima da média geral do catálogo, o que indica atenção consistente de agentes maliciosos ao ecossistema Apache. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão estrutural que tende a se manifestar em múltiplos produtos e versões, exigindo revisão ampla e não pontual. Destaque para CVE-2021-40438, a vulnerabilidade de maior risco ativo no momento, com EPSS máximo de 1,0 — probabilidade de exploração na prática praticamente certa —, o que a torna prioridade imediata de remediação para qualquer organização que opere componentes Apache afetados.

CVE-2022-42467MEDIUMh2 webconsole (available only in prototype mode) should nevertheless be disabled by default.EPSS 1.4%CVE-2023-37544HIGHApache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoSEPSS 1.4%CVE-2022-38370—No authorization of DatabaseConnectController in grafana-connector. EPSS 1.3%CVE-2024-24780CRITICALApache IoTDB: Remote Code Execution with untrusted URI of User-defined functionEPSS 1.3%CVE-2023-26512CRITICALApache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted dataEPSS 1.3%CVE-2023-49735—Apache Tiles: Unvalidated input may lead to path traversal and XXEEPSS 1.3%CVE-2024-28746HIGHApache Airflow: Ignored Airflow PermissionsEPSS 1.3%CVE-2023-47265—Apache Airflow: DAG Params alllow to embed unchecked JavascriptEPSS 1.3%CVE-2021-41832—Content Manipulation with Certificate Validation AttackEPSS 1.3%CVE-2024-45784HIGHApache Airflow: Sensitive configuration values are not masked in the logs by defaultEPSS 1.3%CVE-2024-27140MEDIUMApache Archiva: reflected XSSEPSS 1.3%CVE-2023-40610MEDIUMApache Superset: Privilege escalation with default examples databaseEPSS 1.3%CVE-2023-22665—Apache Jena: Exposure of arbitrary execution in script engine expressions.EPSS 1.3%CVE-2025-31672MEDIUMApache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry namesEPSS 1.3%CVE-2023-24830HIGHApache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorizationEPSS 1.3%CVE-2024-27139HIGHApache Archiva: incorrect authentication potentially leading to account takeoverEPSS 1.3%CVE-2022-47894MEDIUMApache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXEEPSS 1.3%CVE-2022-41672—Session still functional after user is deactivatedEPSS 1.3%CVE-2024-23673HIGHApache Sling Servlets Resolver: Malicious code execution via path traversalEPSS 1.3%CVE-2022-45470HIGHApache Hama allows XSS and information disclosureEPSS 1.3%