Known vulnerabilities in openshift-ansible (Red Hat package) - page 10

Software CPE: cpe:2.3:o:red_hat:openshift-ansible_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 222
Public exploits: 17
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openshift-ansible (Red Hat package) openshift-ansible (Red Hat package) is affected by 222 known vulnerabilities: 18 high, 138 medium, 66 low Critical High Medium Low

Vulnerabilities (222)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73227 - Use of Insufficiently Random Values
CVE-2019-11840
CWE-330 Medium
No
No
3.11.374-1.git.0.92f5956.el7 10.03.2023 SB2019050924
SB2023031017
SB2023031018
and 2 more
#VU60104 - Improper input validation
CVE-2020-8554
CWE-20 Medium
No
No
3.11.374-1.git.0.92f5956.el7 27.01.2022 SB2022012749
SB2022012750
SB2022042257
and 2 more
#VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-21615
CWE-367 Medium
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 26.01.2021 SB2021012623
SB2021021723
SB2021022601
and 1 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21603
CWE-79 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011445
SB2021012106
and 2 more
#VU49526 - XML Injection
CVE-2021-21604
CWE-91 Medium
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011446
SB2021012106
and 2 more
#VU49527 - Exposure of sensitive information to an unauthorized actor
CVE-2021-21602
CWE-200 Medium
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011444
SB2021012106
and 2 more
#VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21605
CWE-22 Medium
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011447
SB2021012106
and 2 more
#VU49529 - Permissions, Privileges, and Access Controls
CVE-2021-21606
CWE-264 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011448
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU48976 - Information Exposure Through Log Files
CVE-2020-8563
CWE-532 Low
No
No
4.6.0-202011260456.p0.git.0.e7caea2.el7 07.12.2020 SB2020121507
SB2020121508
SB2020121509
#VU47403 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26137
CWE-93 Medium
No
No
3.11.374-1.git.0.92f5956.el7 30.09.2020 SB2020100716
SB2020121420
SB2021052028
and 35 more
#VU34130 - Permissions, Privileges, and Access Controls
CVE-2020-8559
CWE-264 Medium
Available
No
3.11.346-1.git.0.f65cc70.el7 22.07.2020 SB2020072221
SB2020120203
SB2020121809
and 6 more
#VU27924 - Incorrect Default Permissions
CVE-2020-1945
CWE-276 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 15.05.2020 SB2020051501
SB2020052114
SB2020060205
and 48 more
#VU47428 - Permissions, Privileges, and Access Controls
CVE-2020-11979
CWE-264 Low
No
No
4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7 14.05.2020 SB2020100804
SB2020100815
SB2020111614
and 51 more
#VU26412 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-11236
CWE-93 Medium
Available
No
4.3.28-202006270952.p0.git.0.c07ec65.el7, 4.4.0-202006271254.p0.git.0.d256229.el7 26.03.2020 SB2020032626
SB2020031827
SB2019091504
and 36 more
#VU35005 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-1002102
CWE-601 Low
No
No
3.11.346-1.git.0.f65cc70.el7 05.12.2019 SB2019120529
SB2020121809
SB2020010218


Showing elements 181 - 200 out of 222