Known vulnerabilities in Multicluster Engine for Kubernetes - page 10

Software CPE: cpe:2.3:a:red_hat:multicluster_engine_for_kubernetes:*:*:*:*:*:*:*:*
Total vulnerabilities: 224
Public exploits: 15
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Multicluster Engine for Kubernetes Multicluster Engine for Kubernetes is affected by 224 known vulnerabilities: 42 high, 138 medium, 44 low Critical High Medium Low

Vulnerabilities (224)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75915 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-2491
CWE-78 High
No
No
2.2.4 09.05.2023 SB20230509106
SB2023051666
SB2023042426
and 17 more
#VU73187 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-27898
CWE-79 Low
No
No
2.2.4 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 2 more
#VU72750 - Inefficient Algorithmic Complexity
CVE-2022-25881
CWE-407 Medium
No
No
2.0.8, 2.1.6, 2.2.3 03.03.2023 SB2023030326
SB2023030328
SB2023031112
and 61 more
#VU72337 - Allocation of Resources Without Limits or Throttling
CVE-2023-23916
CWE-770 Medium
No
No
2.0.7, 2.0.8, 2.1.6, 2.2.3 16.02.2023 SB2023021668
SB2023021670
SB2023021671
and 89 more
#VU72334 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-25725
CWE-444 Medium
No
No
2.2.4 16.02.2023 SB2023021659
SB2023021662
SB2023021663
and 22 more
#VU72250 - Out-of-bounds write
CVE-2023-0767
CWE-787 Medium
No
No
2.0.8, 2.1.6, 2.2.3 15.02.2023 SB2023021549
SB2023021551
SB2023021552
and 84 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
2.0.7, 2.0.8, 2.1.6, 2.2.3 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
2.0.7, 2.0.8, 2.1.6, 2.2.3 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
2.0.7, 2.0.8, 2.1.6, 2.2.3 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
2.0.7, 2.0.8, 2.1.6, 2.2.3 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71499 - Permissions, Privileges, and Access Controls
CVE-2023-24422
CWE-264 Medium
No
No
2.2.4 25.01.2023 SB2023012504
SB2023041270
SB2023041272
and 14 more
#VU71379 - Incorrect Regular Expression
CVE-2022-40897
CWE-185 Medium
No
No
2.1.6 20.01.2023 SB2023012008
SB2023012015
SB2023012016
and 99 more
#VU70461 - Improper Privilege Management
CVE-2022-4415
CWE-269 Low
No
No
2.0.7, 2.1.6 21.12.2022 SB2022122140
SB2022122735
SB2022122816
and 70 more
#VU69392 - Resource exhaustion
CVE-2022-45061
CWE-400 Medium
No
No
2.1.6 16.11.2022 SB2022111650
SB2022112824
SB2022112856
and 125 more
#VU68866 - Improper Authorization
CVE-2022-31692
CWE-285 High
No
No
2.2.4 01.11.2022 SB2022110101
SB2022121119
SB2023011162
and 28 more
#VU68865 - Permissions, Privileges, and Access Controls
CVE-2022-31690
CWE-264 Medium
No
No
2.2.4 01.11.2022 SB2022110101
SB2022121119
SB2023012108
and 9 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Available
Exploited
2.2.4 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU67760 - Type conversion
CVE-2020-10735
CWE-704 Medium
No
No
2.1.6 29.09.2022 SB2022092968
SB2022092970
SB2022093032
and 86 more
#VU67591 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-28861
CWE-601 Low
No
No
2.1.6 22.09.2022 SB2022092243
SB2022092244
SB2022093032
and 76 more
#VU67554 - Server-Side Request Forgery (SSRF)
CVE-2022-3172
CWE-918 Medium
No
No
2.2.4 21.09.2022 SB2022092138
SB2022102614
SB2023011939
and 23 more


Showing elements 181 - 200 out of 224