Known vulnerabilities in Contrail Cloud

Software CPE: cpe:2.3:a:juniper_networks:contrail_cloud:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Contrail Cloud Contrail Cloud is affected by 12 known vulnerabilities: 2 high, 1 medium, 9 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68861 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-3276
CWE-78 Medium
No
No
16.3.0 31.10.2022 SB2022103148
SB2022103162
SB2023011810
and 1 more
#VU68723 - UNIX Symbolic Link (Symlink) Following
CVE-2022-41973
CWE-61 Low
No
No
16.3.0 26.10.2022 SB2022102601
SB2022102602
SB2022102603
and 28 more
#VU68722 - Improper Authorization
CVE-2022-41974
CWE-285 Low
No
No
16.3.0 26.10.2022 SB2022102601
SB2022102602
SB2022102603
and 43 more
#VU66549 - Permissions, Privileges, and Access Controls
CVE-2022-26373
CWE-264 Low
No
No
16.3.0 16.08.2022 SB2022081642
SB2022081647
SB2022081745
and 64 more
#VU66397 - Double Free
CVE-2022-2588
CWE-415 Low
Available
Exploited
16.3.0 11.08.2022 SB2022081109
SB2022081110
SB2022081111
and 99 more
#VU65220 - Processor optimization removal or modification of security-critical code
CVE-2022-29901
CWE-1037 Low
No
No
16.3.0 12.07.2022 SB2022071265
SB2022071302
SB2022071346
and 75 more
#VU65205 - Processor optimization removal or modification of security-critical code
CVE-2022-29900
CWE-1037 Low
No
No
16.3.0 12.07.2022 SB2022071249
SB2022071346
SB2022071602
and 76 more
#VU65204 - Type confusion
CVE-2022-23825
CWE-843 Low
No
No
16.3.0 12.07.2022 SB2022071249
SB2022071256
SB2022071302
and 39 more
#VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30123
CWE-78 High
No
No
16.3.0 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 14 more
#VU57242 - Improper Access Control
CVE-2021-40085
CWE-284 Low
No
No
16.3.0 12.10.2021 SB2021101209
SB2022053134
SB2023051224
and 5 more
#VU55003 - Use of Hard-coded Credentials
CVE-2021-0279
CWE-798 High
No
No
13.6.0 20.07.2021 SB2021072013
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
16.3.0 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more