Known vulnerabilities in openshift-kuryr (Red Hat package) - page 9

Software CPE: cpe:2.3:o:red_hat:openshift-kuryr_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 197
Public exploits: 15
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openshift-kuryr (Red Hat package) openshift-kuryr (Red Hat package) is affected by 197 known vulnerabilities: 17 high, 113 medium, 67 low Critical High Medium Low

Vulnerabilities (197)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73227 - Use of Insufficiently Random Values
CVE-2019-11840
CWE-330 Medium
No
No
3.11.374-1.git.1478.ef11824.el7 10.03.2023 SB2019050924
SB2023031017
SB2023031018
and 2 more
#VU60104 - Improper input validation
CVE-2020-8554
CWE-20 Medium
No
No
3.11.374-1.git.1478.ef11824.el7 27.01.2022 SB2022012749
SB2022012750
SB2022042257
and 2 more
#VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-21615
CWE-367 Medium
No
No
4.6.0-202102031810.p0.git.2225.a3ab872.el8 26.01.2021 SB2021012623
SB2021021723
SB2021022601
and 1 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
4.6.0-202102031810.p0.git.2225.a3ab872.el8 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
4.6.0-202102031810.p0.git.2225.a3ab872.el8 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
4.6.0-202102031810.p0.git.2225.a3ab872.el8 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
4.6.0-202102031810.p0.git.2225.a3ab872.el8 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
4.6.0-202102031810.p0.git.2225.a3ab872.el8 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU48976 - Information Exposure Through Log Files
CVE-2020-8563
CWE-532 Low
No
No
4.6.0-202012042155.p0.git.2216.8a6f6a5.el8 07.12.2020 SB2020121507
SB2020121508
SB2020121509
#VU48977 - Information Exposure Through Log Files
CVE-2020-8564
CWE-532 Low
No
No
3.11.501-1.git.c33a657.el7, 4.6.0-202101151835.p0.git.2220.40847e5.el8 07.12.2020 SB2020121507
SB2020121509
SB2020121808
and 6 more
#VU48231 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-2304
CWE-611 Medium
No
No
4.4.0-202101082241.p0.git.1821.1a159eb.el8 04.11.2020 SB2020110942
SB2021020406
#VU48232 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-2305
CWE-611 Medium
No
No
4.4.0-202101082241.p0.git.1821.1a159eb.el8 04.11.2020 SB2020110943
SB2021020406
#VU47403 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26137
CWE-93 Medium
No
No
3.11.374-1.git.1478.ef11824.el7 30.09.2020 SB2020100716
SB2020121420
SB2021052028
and 35 more
#VU34130 - Permissions, Privileges, and Access Controls
CVE-2020-8559
CWE-264 Medium
Available
No
3.11.346-1.git.1478.b99caab.el7 22.07.2020 SB2020072221
SB2020120203
SB2020121809
and 6 more
#VU30129 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2223
CWE-79 Low
No
No
4.4.0-202008131757.p0.git.1813.8e0365d.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071911
and 2 more
#VU30128 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2222
CWE-79 Low
No
No
4.4.0-202008131757.p0.git.1813.8e0365d.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071910
and 2 more
#VU30127 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2221
CWE-79 Low
No
No
4.4.0-202008131757.p0.git.1813.8e0365d.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071909
and 2 more
#VU30126 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2220
CWE-79 Low
No
No
4.4.0-202008131757.p0.git.1813.8e0365d.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071908
and 2 more
#VU26412 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-11236
CWE-93 Medium
Available
No
4.3.28-202006270952.p0.git.1632.9e3ea83.el8, 4.4.0-202006271254.p0.git.1811.c15bfa2.el8 26.03.2020 SB2020032626
SB2020031827
SB2019091504
and 36 more
#VU35005 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-1002102
CWE-601 Low
No
No
3.11.346-1.git.1478.b99caab.el7 05.12.2019 SB2019120529
SB2020121809
SB2020010218


Showing elements 161 - 180 out of 197