Known vulnerabilities in ignition (Red Hat package) - page 5
Vendor:
Red Hat Inc.
Software:
ignition (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:ignition_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
100
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.21.0-7.el9_6
2.18.0-10.rhaos4.17.el9
2.16.2-7.rhaos4.15.el9
2.18.0-7.rhaos4.16.el9
2.18.0-8.rhaos4.18.el9
2.21.0-4.rhaos4.19.el9
2.16.2-5.rhaos4.14.el9
2.14.0-10.rhaos4.12.el8
2.14.0-8.rhaos4.12.el9
2.15.0-10.rhaos4.13.el9
2.16.2-6.rhaos4.15.el9
2.18.0-5.rhaos4.16.el9
2.16.2-5.rhaos4.15.el9
2.15.0-9.rhaos4.13.el9
2.16.2-4.rhaos4.14.el9
2.14.0-9.rhaos4.12.el8
2.14.0-7.rhaos4.12.el9
2.18.0-2.1.rhaos4.16.el9
2.15.0-7.2.rhaos4.13.el9
2.16.2-2.2.rhaos4.15.el9
2.14.0-7.2.rhaos4.12.el8
2.14.0-5.3.rhaos4.12.el9
2.15.0-7.1.rhaos4.13.el9
2.16.2-2.1.rhaos4.14.el9
2.14.0-7.1.rhaos4.12.el8
2.14.0-5.2.rhaos4.12.el9
2.16.2-2.1.rhaos4.15.el9
2.16.2-2.rhaos4.15.el9
2.14.0-5.1.rhaos4.11.el8
2.14.0-6.1.rhaos4.12.el8
2.14.0-5.1.rhaos4.12.el9
2.16.2-1.1.rhaos4.14.el9
2.6.0-8.rhaos4.6.git947598e.el8
2.9.0-7.rhaos4.8.el8
2.9.0-2.rhaos4.7.git1d56dc8.el8
2.6.0-5.rhaos4.6.git947598e.el8
0.34.0-1.rhaos4.3.git92f874c.el8
2.14.0-5.rhaos4.12.el8
2.14.0-5.rhaos4.12.el9
2.14.0-5.rhaos4.11.el8
2.14.0-1.el9
2.14.0-4.rhaos4.11.el8
2.14.0-3.rhaos4.11.el8
2.6.0-9.rhaos4.6.git947598e.el8
2.9.0-5.rhaos4.7.git1d56dc8.el8
2.9.0-8.rhaos4.8.1.el8
2.13.0-2.rhaos4.10.el8
2.12.0-3.rhaos4.9.el8
2.6.0-7.rhaos4.6.git947598e.el8
2.12.0-1.rhaos4.9.el8
2.9.0-4.rhaos4.7.git1d56dc8.el8
2.9.0-6.rhaos4.8.el8
2.9.0-3.rhaos4.7.git1d56dc8.el8
0.35.1-12.rhaos4.5.gitb4d18ad.el8
0.33.0-6.rhaos4.2.gitc65e95c.el8
0.33.0-5.rhaos4.2.gitc65e95c.el8
0.34.0-2.rhaos4.3.git92f874c.el8
0.34.0-4.rhaos4.3.git92f874c.el8
0.32.0-2.git5941fc0.el8
Vulnerabilities (100)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU56245 - Improper input validation CVE-2021-25735 |
CWE-20 | Medium | 2.9.0-6.rhaos4.8.el8 | 01.09.2021 |
SB2021090125 SB2021090126 SB2022083132 and 4 more |
||
| #VU56243 - Improper Authentication CVE-2021-3636 |
CWE-287 | Low | 2.9.0-6.rhaos4.8.el8 | 01.09.2021 |
SB2021090123 SB2021090126 SB2022083132 and 1 more |
||
| #VU56023 - Missing Authorization CVE-2021-33197 |
CWE-862 | Medium | 2.6.0-8.rhaos4.6.git947598e.el8, 2.9.0-4.rhaos4.7.git1d56dc8.el8, 2.9.0-7.rhaos4.8.el8 | 22.08.2021 |
SB2021070405 SB2021082204 SB2021083116 and 41 more |
||
| #VU54910 - Uncontrolled Recursion CVE-2021-31525 |
CWE-674 | Medium | 2.9.0-7.rhaos4.8.el8 | 15.07.2021 |
SB2021071514 SB2021052725 SB2021071515 and 39 more |
||
| #VU54521 - Resource exhaustion CVE-2021-33196 |
CWE-400 | Medium | 2.9.0-7.rhaos4.8.el8, 2.12.0-1.rhaos4.9.el8 | 04.07.2021 |
SB2021070405 SB2021070406 SB2021071515 and 37 more |
||
| #VU53436 - Exposure of sensitive information to an unauthorized actor CVE-2021-25737 |
CWE-200 | Low | 2.9.0-6.rhaos4.8.el8 | 24.05.2021 |
SB2021052409 SB2021060911 SB2021090126 and 4 more |
||
| #VU53152 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21648 |
CWE-79 | Low | 2.9.0-6.rhaos4.8.el8 | 12.05.2021 |
SB2021051209 SB2021090126 SB2022083132 and 1 more |
||
| #VU52902 - Improper Validation of Array Index CVE-2021-3121 |
CWE-129 | High | 2.9.0-6.rhaos4.8.el8 | 06.05.2021 |
SB2021011120 SB2021050602 SB2021050603 and 34 more |
||
| #VU51994 - Improper Authentication CVE-2021-21640 |
CWE-287 | Low | 2.9.0-6.rhaos4.8.el8 | 08.04.2021 |
SB2021040814 SB2021052527 SB2021062509 and 3 more |
||
| #VU51993 - Improper input validation CVE-2021-21639 |
CWE-20 | Low | 2.9.0-6.rhaos4.8.el8 | 08.04.2021 |
SB2021040814 SB2021052527 SB2021062509 and 3 more |
||
| #VU51878 - Exposure of sensitive information to an unauthorized actor CVE-2021-28163 |
CWE-200 | Medium | 2.9.0-3.rhaos4.7.git1d56dc8.el8 | 01.04.2021 |
SB2021040179 SB2021050704 SB2021051321 and 27 more |
||
| #VU51876 - Resource exhaustion CVE-2021-28165 |
CWE-400 | Medium | 2.9.0-3.rhaos4.7.git1d56dc8.el8 | 01.04.2021 |
SB2021040179 SB2021042208 SB2021050704 and 56 more |
||
| #VU51595 - Permissions, Privileges, and Access Controls CVE-2021-21623 |
CWE-264 | Medium | 2.9.0-6.rhaos4.8.el8 | 22.03.2021 |
SB2021032207 SB2021090126 SB2022083132 and 1 more |
||
| #VU50047 - Incorrect Calculation CVE-2021-3114 |
CWE-682 | Medium | 2.6.0-7.rhaos4.6.git947598e.el8, 2.9.0-3.rhaos4.7.git1d56dc8.el8, 2.9.0-6.rhaos4.8.el8 | 26.01.2021 |
SB2021012714 SB2021012715 SB20210120130 and 40 more |
||
| #VU48480 - Improper input validation CVE-2020-28362 |
CWE-20 | Medium | 2.9.0-3.rhaos4.7.git1d56dc8.el8 | 17.11.2020 |
SB2020111715 SB2020111716 SB2020111225 and 30 more |
||
| #VU45699 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2020-16845 |
CWE-835 | Medium | 0.35.1-12.rhaos4.5.gitb4d18ad.el8 | 14.08.2020 |
SB2020081403 SB2020081404 SB2020081405 and 44 more |
||
| #VU31891 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-15586 |
CWE-362 | Medium | 0.35.1-12.rhaos4.5.gitb4d18ad.el8 | 27.07.2020 |
SB2020072734 SB2020072735 SB2020072749 and 37 more |
||
| #VU26474 - Uncontrolled Memory Allocation CVE-2020-8552 |
CWE-789 | Medium | 0.34.0-4.rhaos4.3.git92f874c.el8 | 31.03.2020 |
SB2020033111 SB2020040174 SB2020042251 and 6 more |
||
| #VU25458 - Heap-based Buffer Overflow CVE-2020-7039 |
CWE-122 | Low | 0.34.0-2.rhaos4.3.git92f874c.el8 | 19.02.2020 |
SB2020021912 SB2020031117 SB2020031053 and 25 more |
||
| #VU25457 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-7211 |
CWE-22 | Low | 0.34.0-2.rhaos4.3.git92f874c.el8 | 19.02.2020 |
SB2020021912 SB2020021193 |
Showing elements 81 - 100 out of 100