Known vulnerabilities in machine-config-daemon (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:machine-config-daemon_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 47
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting machine-config-daemon (Red Hat package) machine-config-daemon (Red Hat package) is affected by 47 known vulnerabilities: 2 high, 20 medium, 25 low Critical High Medium Low

Vulnerabilities (47)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU52502 - Improper input validation
CVE-2020-27218
CWE-20 Medium
No
No
4.5.0-202106011407.p0.git.f003424.el8 23.04.2021 SB2021042305
SB2021042635
SB2021063002
and 15 more
#VU52495 - Permissions, Privileges, and Access Controls
CVE-2021-21645
CWE-264 Low
No
No
4.5.0-202106011407.p0.git.f003424.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52494 - Cross-Site Request Forgery (CSRF)
CVE-2021-21644
CWE-352 Low
No
No
4.5.0-202106011407.p0.git.f003424.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52493 - Permissions, Privileges, and Access Controls
CVE-2021-21643
CWE-264 Low
No
No
4.5.0-202106011407.p0.git.f003424.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52492 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-21642
CWE-611 Medium
No
No
4.5.0-202106011407.p0.git.f003424.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52385 - Improper input validation
CVE-2020-27223
CWE-20 Medium
Available
No
4.5.0-202106011407.p0.git.f003424.el8 21.04.2021 SB2021042107
SB2021063002
SB2021063034
and 19 more
#VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-21615
CWE-367 Medium
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 26.01.2021 SB2021012623
SB2021021723
SB2021022601
and 1 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21603
CWE-79 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011445
SB2021012106
and 2 more
#VU49526 - XML Injection
CVE-2021-21604
CWE-91 Medium
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011446
SB2021012106
and 2 more
#VU49527 - Exposure of sensitive information to an unauthorized actor
CVE-2021-21602
CWE-200 Medium
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011444
SB2021012106
and 2 more
#VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21605
CWE-22 Medium
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011447
SB2021012106
and 2 more
#VU49529 - Permissions, Privileges, and Access Controls
CVE-2021-21606
CWE-264 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011448
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU48942 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-27216
CWE-362 Low
No
No
4.5.0-202106011407.p0.git.f003424.el8 23.10.2020 SB2020121307
SB2020121308
SB2021012011
and 27 more
#VU27924 - Incorrect Default Permissions
CVE-2020-1945
CWE-276 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 15.05.2020 SB2020051501
SB2020052114
SB2020060205
and 48 more
#VU47428 - Permissions, Privileges, and Access Controls
CVE-2020-11979
CWE-264 Low
No
No
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 14.05.2020 SB2020100804
SB2020100815
SB2020111614
and 51 more


Showing elements 1 - 20 out of 47