Known vulnerabilities in Multicluster Engine for Kubernetes - page 8

Software CPE: cpe:2.3:a:red_hat:multicluster_engine_for_kubernetes:*:*:*:*:*:*:*:*
Total vulnerabilities: 224
Public exploits: 15
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Multicluster Engine for Kubernetes Multicluster Engine for Kubernetes is affected by 224 known vulnerabilities: 42 high, 138 medium, 44 low Critical High Medium Low

Vulnerabilities (224)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81453 - Use After Free
CVE-2023-4813
CWE-416 Medium
No
No
2.1.9, 2.2.9, 2.3.3 04.10.2023 SB2023100435
SB2023100579
SB2023100581
and 91 more
#VU81447 - Use After Free
CVE-2023-4806
CWE-416 Medium
No
No
2.1.9, 2.2.9, 2.3.3 03.10.2023 SB2023100363
SB2023100402
SB2023100418
and 97 more
#VU81437 - Memory corruption
CVE-2023-4911
CWE-119 Low
Available
Exploited
2.1.9, 2.2.9, 2.3.3 03.10.2023 SB2023100343
SB2023100345
SB2023100402
and 94 more
#VU81097 - Out-of-bounds read
CVE-2023-4527
CWE-125 Medium
No
No
2.1.9, 2.2.9, 2.3.3 25.09.2023 SB2023092525
SB2023100345
SB2023100402
and 79 more
#VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-26136
CWE-1321 High
No
No
2.3.2 04.09.2023 SB2023090411
SB2023090423
SB2023090816
and 42 more
#VU80228 - Cleartext Transmission of Sensitive Information
CVE-2023-40217
CWE-319 Medium
No
No
2.1.9, 2.2.9, 2.3.3 01.09.2023 SB2023090142
SB2023090143
SB2023090144
and 139 more
#VU80135 - Security Features
CVE-2023-37466
CWE-254 High
Available
No
2.1.8, 2.3.1 30.08.2023 SB2023083012
SB2023083025
SB2023083028
and 7 more
#VU79878 - Incorrect Authorization
CVE-2023-3899
CWE-863 Low
No
No
2.3.2 23.08.2023 SB2023082308
SB2023082309
SB2023082310
and 44 more
#VU79504 - Security Features
CVE-2023-37903
CWE-254 Medium
No
No
2.1.8, 2.2.7, 2.3.1 15.08.2023 SB2023081515
SB2023081517
SB2023081602
and 9 more
#VU78490 - Permissions, Privileges, and Access Controls
CVE-2023-34969
CWE-264 Low
No
No
2.1.8, 2.2.7, 2.3.2 21.07.2023 SB2023072119
SB2023072121
SB2023072122
and 61 more
#VU78454 - Untrusted Search Path
CVE-2023-38408
CWE-426 Medium
Available
No
2.1.8, 2.2.7 20.07.2023 SB2023072068
SB2023072073
SB2023072074
and 73 more
#VU78005 - Inadequate Encryption Strength
CVE-2023-3089
CWE-326 Medium
No
No
2.1.8, 2.2.7, 2.3.1 06.07.2023 SB2023070602
SB2023070603
SB2023070604
and 34 more
#VU75792 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-29400
CWE-79 Medium
No
No
2.3.2 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 74 more
#VU75791 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24540
CWE-94 Medium
No
No
2.3.2 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 81 more
#VU75790 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-24539
CWE-79 Medium
No
No
2.3.2 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 75 more
#VU75432 - Permissions, Privileges, and Access Controls
CVE-2023-30630
CWE-264 Low
No
No
2.1.9, 2.2.9, 2.3.2 24.04.2023 SB2023042410
SB2023042412
SB2023042642
and 51 more
#VU75141 - Memory corruption
CVE-2023-29491
CWE-119 Low
No
No
2.1.9, 2.2.9, 2.3.2, 2.3.3, 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4 14.04.2023 SB2023041454
SB2023052328
SB2023052346
and 132 more
#VU73829 - State Issues
CVE-2023-27536
CWE-371 Medium
No
No
2.1.8, 2.2.7 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 80 more
#VU72886 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-41721
CWE-444 Medium
No
No
2.3.2 06.03.2023 SB2023030655
SB2023030656
SB2023030657
and 39 more
#VU72618 - Improper input validation
CVE-2023-24329
CWE-20 Medium
No
No
2.1.8 28.02.2023 SB2023022819
SB2023022822
SB2023030832
and 158 more


Showing elements 141 - 160 out of 224