Known vulnerabilities in fence-agents (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:fence-agents_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 24
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting fence-agents (Red Hat package) fence-agents (Red Hat package) is affected by 24 known vulnerabilities: 2 high, 15 medium, 7 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135769 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-59939
CWE-409 Medium
No
No
4.2.1-89.el8_6.24, 4.2.1-112.el8_8.19, 4.10.0-62.el9_4.27, 4.10.0-86.el9_6.19, 4.16.0-5.el10_0.12, 4.16.0-21.el10_2.5 29.06.2026 SB2026062991
SB2026072355
SB2026073009
and 8 more
#VU130907 - Exposure of sensitive information to an unauthorized actor
CVE-2026-44431
CWE-200 Medium
No
No
4.2.1-65.el8_4.31, 4.2.1-89.el8_6.25, 4.2.1-112.el8_8.20, 4.2.1-129.el8_10.28 09.05.2026 SB20260509126
SB2026051588
SB2026051589
and 40 more
#VU128152 - Uncontrolled Recursion
CVE-2026-30922
CWE-674 Medium
No
No
4.2.1-129.el8_10.25, 4.10.0-43.el9_2.22, 4.10.0-86.el9_6.17, 4.10.0-98.el9_7.13, 4.16.0-5.el10_0.9, 4.16.0-13.el10_1.4 27.04.2026 SB20260427104
SB20260427114
SB20260427115
and 28 more
#VU128143 - Insufficient Verification of Data Authenticity
CVE-2026-32597
CWE-345 Medium
No
No
4.2.1-129.el8_10.25, 4.10.0-43.el9_2.21, 4.10.0-62.el9_4.24, 4.10.0-98.el9_7.12, 4.16.0-5.el10_0.9, 4.16.0-13.el10_1.4 27.04.2026 SB20260427100
SB20260427131
SB20260427132
and 12 more
#VU124874 - Insufficient Verification of Data Authenticity
CVE-2026-26007
CWE-345 Medium
No
No
4.2.1-129.el8_10.25, 4.10.0-43.el9_2.21, 4.10.0-62.el9_4.24, 4.10.0-98.el9_7.12 06.04.2026 SB2026040616
SB2026040617
SB2026040618
and 30 more
#VU122270 - Resource exhaustion
CVE-2026-23490
CWE-400 Medium
No
No
4.2.1-65.el8_4.27, 4.2.1-89.el8_6.21, 4.10.0-20.el9_0.28, 4.10.0-43.el9_2.19, 4.16.0-5.el10_0.8 03.02.2026 SB2026020365
SB2026020366
SB2026020370
and 52 more
#VU121072 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-21441
CWE-409 Medium
No
No
4.2.1-65.el8_4.25, 4.2.1-89.el8_6.20, 4.2.1-112.el8_8.15, 4.10.0-20.el9_0.27, 4.10.0-43.el9_2.18, 4.10.0-62.el9_4.21, 4.10.0-86.el9_6.14 07.01.2026 SB2026010780
SB2026011269
SB2026011328
and 89 more
#VU119231 - Resource exhaustion
CVE-2025-66471
CWE-400 Medium
No
No
4.2.1-65.el8_4.25, 4.2.1-89.el8_6.20, 4.2.1-112.el8_8.15, 4.10.0-20.el9_0.27, 4.10.0-43.el9_2.18, 4.10.0-62.el9_4.21, 4.10.0-86.el9_6.14 05.12.2025 SB2025120581
SB2025121208
SB2026011313
and 88 more
#VU119230 - Allocation of Resources Without Limits or Throttling
CVE-2025-66418
CWE-770 Medium
No
No
4.2.1-65.el8_4.24, 4.2.1-89.el8_6.19, 4.2.1-112.el8_8.14, 4.10.0-20.el9_0.26, 4.10.0-43.el9_2.17, 4.10.0-86.el9_6.13 05.12.2025 SB2025120581
SB2025121208
SB2025121938
and 93 more
#VU111716 - Insufficiently Protected Credentials
CVE-2024-47081
CWE-522 Medium
No
No
4.2.1-65.el8_4.21, 4.2.1-89.el8_6.15, 4.2.1-112.el8_8.11, 4.2.1-129.el8_10.14 21.06.2025 SB2025062111
SB2025062112
SB2025062113
and 95 more
#VU109840 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-47273
CWE-22 High
No
No
4.10.0-20.el9_0.23, 4.10.0-43.el9_2.14, 4.10.0-62.el9_4.15, 4.10.0-86.el9_6.7 27.05.2025 SB2025052721
SB2025052734
SB2025052736
and 112 more
#VU105387 - Improper input validation
CVE-2025-27516
CWE-20 Low
No
No
4.10.0-62.el9_4.11 06.03.2025 SB2025030628
SB2025031001
SB2025031002
and 83 more
#VU101972 - Security Features
CVE-2024-56326
CWE-254 Low
No
No
4.10.0-20.el9_0.20, 4.10.0-43.el9_2.11, 4.10.0-62.el9_4.10, 4.10.0-76.el9_5.4 27.12.2024 SB2024122789
SB2024122790
SB2024122791
and 78 more
#VU101971 - Security Features
CVE-2024-56201
CWE-254 Low
No
No
4.10.0-20.el9_0.20, 4.10.0-43.el9_2.11, 4.10.0-62.el9_4.10, 4.10.0-76.el9_5.4 27.12.2024 SB2024122789
SB2025010203
SB2025010322
and 62 more
#VU95339 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-6345
CWE-94 High
No
No
4.2.1-65.el8_4.20, 4.2.1-89.el8_6.14, 4.2.1-112.el8_8.8, 4.2.1-129.el8_10.4, 4.10.0-20.el9_0.17, 4.10.0-43.el9_2.9, 4.10.0-62.el9_4.5 05.08.2024 SB2024080590
SB2024080593
SB2024080594
and 160 more
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
4.2.1-129.el8_10.4 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 194 more
#VU89677 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-34064
CWE-79 Medium
No
No
4.2.1-65.el8_4.15, 4.2.1-89.el8_6.12, 4.2.1-112.el8_8.6, 4.10.0-20.el9_0.13, 4.10.0-62.el9_4.3 20.05.2024 SB2024052067
SB2024052081
SB2024052082
and 83 more
#VU85747 - Observable discrepancy
CVE-2023-52323
CWE-203 Low
No
No
4.2.1-129.el8, 4.10.0-20.el9_0.11, 4.10.0-62.el9 24.01.2024 SB2024012414
SB2024012416
SB2024022053
and 24 more
#VU85368 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-22195
CWE-79 Medium
No
No
4.2.1-129.el8, 4.10.0-20.el9_0.11, 4.10.0-62.el9 15.01.2024 SB2024011508
SB2024011512
SB2024011513
and 60 more
#VU82978 - Exposure of sensitive information to an unauthorized actor
CVE-2023-45803
CWE-200 Medium
No
No
4.2.1-129.el8, 4.10.0-20.el9_0.11, 4.10.0-62.el9 10.11.2023 SB2023111038
SB2023111040
SB2023111048
and 122 more


Showing elements 1 - 20 out of 24