Known vulnerabilities in machine-config-daemon (Red Hat package)
Vendor:
Red Hat Inc.
Software:
machine-config-daemon (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:machine-config-daemon_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
47
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.5.0-202101080743.p0.git.2585.5bf8919.el8
4.6.0-202007100531.p0.git.2669.abe1720.el8
4.3.40-202010141211.p0.git.2190.6610e26.el8
4.3.28-202006270952.p0.git.2178.08d8005.el8
4.4.0-202006271254.p0.git.2337.29601a9.el8
4.5.0-202007012112.p0.git.2527.d12c3da.el8
4.3.0-202001131753.git.1.e2edc36.el8
4.5.0-202106011407.p0.git.f003424.el8
4.5.0-202012050338.p0.git.2581.e7a62a7.el8
4.5.0-202102050524.p0.git.2594.ff3b8c0.el8
4.5.0-202010012007.p0.git.2570.fc7c941.el8
4.3.30-202007230708.p0.git.2188.9f34d7f.el8
4.3.10-202003300415.git.0.56d6ae0.el8
4.3.25-202006081518.git.1.478b31a.el8
4.4.0-202008130707.p0.git.2357.47d462a.el8
4.4.0-202007092124.p0.git.2349.08d34d1.el8
4.2.0-201907161330.git.1.bf8077c.el8
4.4.0-202006080017.git.1.32e0736.el8
4.3.1-202002031701.git.1.0ad9b3b.el8
4.3.9-202003230116.git.0.26e7ac9.el8
4.2.20-202002170402.git.1.a83336a.el8
4.3.3-202002170501.git.1.6b1b155.el8
4.3.5-202003020117.git.0.61e0e48.el8
Vulnerabilities (47)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU52502 - Improper input validation CVE-2020-27218 |
CWE-20 | Medium | 4.5.0-202106011407.p0.git.f003424.el8 | 23.04.2021 |
SB2021042305 SB2021042635 SB2021063002 and 15 more |
||
| #VU52495 - Permissions, Privileges, and Access Controls CVE-2021-21645 |
CWE-264 | Low | 4.5.0-202106011407.p0.git.f003424.el8 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52494 - Cross-Site Request Forgery (CSRF) CVE-2021-21644 |
CWE-352 | Low | 4.5.0-202106011407.p0.git.f003424.el8 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52493 - Permissions, Privileges, and Access Controls CVE-2021-21643 |
CWE-264 | Low | 4.5.0-202106011407.p0.git.f003424.el8 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52492 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-21642 |
CWE-611 | Medium | 4.5.0-202106011407.p0.git.f003424.el8 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52385 - Improper input validation CVE-2020-27223 |
CWE-20 | Medium | 4.5.0-202106011407.p0.git.f003424.el8 | 21.04.2021 |
SB2021042107 SB2021063002 SB2021063034 and 19 more |
||
| #VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2021-21615 |
CWE-367 | Medium | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 26.01.2021 |
SB2021012623 SB2021021723 SB2021022601 and 1 more |
||
| #VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21611 |
CWE-79 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 14.01.2021 |
SB2021011418 SB2021011453 SB2021012106 and 2 more |
||
| #VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21610 |
CWE-79 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 14.01.2021 |
SB2021011418 SB2021011452 SB2021012106 and 2 more |
||
| #VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21608 |
CWE-79 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 14.01.2021 |
SB2021011418 SB2021011450 SB2021012106 and 2 more |
||
| #VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21603 |
CWE-79 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011445 SB2021012106 and 2 more |
||
| #VU49526 - XML Injection CVE-2021-21604 |
CWE-91 | Medium | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011446 SB2021012106 and 2 more |
||
| #VU49527 - Exposure of sensitive information to an unauthorized actor CVE-2021-21602 |
CWE-200 | Medium | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011444 SB2021012106 and 2 more |
||
| #VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-21605 |
CWE-22 | Medium | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011447 SB2021012106 and 2 more |
||
| #VU49529 - Permissions, Privileges, and Access Controls CVE-2021-21606 |
CWE-264 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011448 SB2021012106 and 2 more |
||
| #VU49530 - Memory corruption CVE-2021-21607 |
CWE-119 | Medium | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011449 SB2021012106 and 2 more |
||
| #VU49531 - Permissions, Privileges, and Access Controls CVE-2021-21609 |
CWE-264 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 13.01.2021 |
SB2021011418 SB2021011451 SB2021012106 and 2 more |
||
| #VU48942 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-27216 |
CWE-362 | Low | 4.5.0-202106011407.p0.git.f003424.el8 | 23.10.2020 |
SB2020121307 SB2020121308 SB2021012011 and 27 more |
||
| #VU27924 - Incorrect Default Permissions CVE-2020-1945 |
CWE-276 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 15.05.2020 |
SB2020051501 SB2020052114 SB2020060205 and 48 more |
||
| #VU47428 - Permissions, Privileges, and Access Controls CVE-2020-11979 |
CWE-264 | Low | 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | 14.05.2020 |
SB2020100804 SB2020100815 SB2020111614 and 51 more |
Showing elements 1 - 20 out of 47