Known vulnerabilities in atomic-enterprise-service-catalog (Red Hat package) - page 3

Software CPE: cpe:2.3:o:red_hat:atomic-enterprise-service-catalog_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 71
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting atomic-enterprise-service-catalog (Red Hat package) atomic-enterprise-service-catalog (Red Hat package) is affected by 71 known vulnerabilities: 11 high, 40 medium, 20 low Critical High Medium Low

Vulnerabilities (71)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73227 - Use of Insufficiently Random Values
CVE-2019-11840
CWE-330 Medium
No
No
3.11.374-1.git.1675.738abcc.el7 10.03.2023 SB2019050924
SB2023031017
SB2023031018
and 2 more
#VU60104 - Improper input validation
CVE-2020-8554
CWE-20 Medium
No
No
3.11.374-1.git.1675.738abcc.el7 27.01.2022 SB2022012749
SB2022012750
SB2022042257
and 2 more
#VU53399 - Security Features
CVE-2021-30465
CWE-254 Low
No
No
3.11.452-1.git.2e6be86.el7 20.05.2021 SB2021052013
SB2021052014
SB2021052015
and 33 more
#VU51604 - Improper Validation of Certificate with Host Mismatch
CVE-2021-28363
CWE-297 Medium
No
No
3.11.420-1.git.1675.fc6e217.el7 22.03.2021 SB2021032215
SB2021052523
SB2021071501
and 9 more
#VU50957 - Integer overflow
CVE-2020-27813
CWE-190 Medium
No
No
3.11.404-1.git.1675.3094ee9.el7 25.02.2021 SB2020120224
SB2021052527
SB2023070702
and 3 more
#VU47403 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26137
CWE-93 Medium
No
No
3.11.374-1.git.1675.738abcc.el7 30.09.2020 SB2020100716
SB2020121420
SB2021052028
and 35 more
#VU45699 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-16845
CWE-835 Medium
No
No
4.4.0-202011122017.p0.git.1806.53dc206.el7, 4.5.0-202010081312.p0.git.1808.498e523.el7, 4.5.0-202011121956.p0.git.1808.0eb4933.el7 14.08.2020 SB2020081403
SB2020081404
SB2020081405
and 44 more
#VU31891 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-15586
CWE-362 Medium
No
No
4.4.0-202011122017.p0.git.1806.53dc206.el7, 4.5.0-202010081312.p0.git.1808.498e523.el7, 4.5.0-202011121956.p0.git.1808.0eb4933.el7 27.07.2020 SB2020072734
SB2020072735
SB2020072749
and 37 more
#VU34130 - Permissions, Privileges, and Access Controls
CVE-2020-8559
CWE-264 Medium
Available
No
3.11.346-1.git.1675.f80310c.el7 22.07.2020 SB2020072221
SB2020120203
SB2020121809
and 6 more
#VU26474 - Uncontrolled Memory Allocation
CVE-2020-8552
CWE-789 Medium
No
No
4.3.9-202003230116.git.0.57d5c98.el7 31.03.2020 SB2020033111
SB2020040174
SB2020042251
and 6 more
#VU26412 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-11236
CWE-93 Medium
Available
No
4.3.28-202006270952.p0.git.1806.b12beb7.el7, 4.4.0-202006271254.p0.git.1806.44e1f58.el7 26.03.2020 SB2020032626
SB2020031827
SB2019091504
and 36 more
#VU26393 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2163
CWE-79 Low
No
No
4.3.25-202006081518.git.1.52b3a66.el7, 4.4.0-202006080017.git.1.77a5cc9.el7 26.03.2020 SB2020032622
SB2020032668
SB2020061738
and 1 more
#VU26392 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2162
CWE-79 Low
No
No
4.3.25-202006081518.git.1.52b3a66.el7, 4.4.0-202006080017.git.1.77a5cc9.el7 26.03.2020 SB2020032622
SB2020032667
SB2020061738
and 1 more
#VU26391 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2161
CWE-79 Low
No
No
4.3.25-202006081518.git.1.52b3a66.el7, 4.4.0-202006080017.git.1.77a5cc9.el7 26.03.2020 SB2020032622
SB2020032662
SB2020061738
and 1 more
#VU26390 - Cross-Site Request Forgery (CSRF)
CVE-2020-2160
CWE-352 Low
No
No
4.3.25-202006081518.git.1.52b3a66.el7, 4.4.0-202006080017.git.1.77a5cc9.el7 26.03.2020 SB2020032622
SB2020032661
SB2020061738
and 1 more
#VU25501 - Use After Free
CVE-2020-8945
CWE-416 High
No
No
4.3.10-202003300415.git.0.68d5fb7.el7 21.02.2020 SB2020022110
SB2020031116
SB2020031126
and 23 more
#VU24764 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2020-2105
CWE-451 Low
No
No
4.3.5-202003020117.git.0.4eb885c.el7 30.01.2020 SB2020013005
SB20200310153
#VU24758 - Improper Authentication
CVE-2020-2099
CWE-287 High
No
No
4.3.5-202003020117.git.0.4eb885c.el7 30.01.2020 SB2020013004
SB20200310153
#VU35005 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-1002102
CWE-601 Low
No
No
3.11.346-1.git.1675.f80310c.el7 05.12.2019 SB2019120529
SB2020121809
SB2020010218
#VU21780 - Improper Certificate Validation
CVE-2019-11324
CWE-295 Medium
Available
No
4.3.28-202006270952.p0.git.1806.b12beb7.el7, 4.4.0-202006271254.p0.git.1806.44e1f58.el7 15.10.2019 SB2019041823
SB2020031827
SB2019091504
and 19 more


Showing elements 41 - 60 out of 71