Known vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) - page 15

Software CPE: cpe:2.3:a:red_hat:openshift_container_storage:*:*:*:*:*:*:*:*
Total vulnerabilities: 476
Public exploits: 35
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Data Foundation (formerly OpenShift Container Storage) OpenShift Data Foundation (formerly OpenShift Container Storage) is affected by 476 known vulnerabilities: 1 critical, 90 high, 246 medium, 139 low Critical High Medium Low

Vulnerabilities (476)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75915 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-2491
CWE-78 High
No
No
4.11.9, 4.12.4, 4.13.0 09.05.2023 SB20230509106
SB2023051666
SB2023042426
and 17 more
#VU74578 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28617
CWE-78 High
No
No
4.12.3 06.04.2023 SB2023040682
SB2023040684
SB2023042105
and 20 more
#VU73828 - State Issues
CVE-2023-27535
CWE-371 Low
No
No
4.11.9, 4.12.3, 4.12.4 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 84 more
#VU72432 - Heap-based Buffer Overflow
CVE-2022-48303
CWE-122 High
No
No
4.11.7, 4.12.2, 4.13.0 21.02.2023 SB2023022105
SB2023022111
SB2023022112
and 72 more
#VU72337 - Allocation of Resources Without Limits or Throttling
CVE-2023-23916
CWE-770 Medium
No
No
4.11.7, 4.12.2 16.02.2023 SB2023021668
SB2023021670
SB2023021671
and 89 more
#VU72125 - Inadequate Encryption Strength
CVE-2023-0361
CWE-326 Medium
No
No
4.11.7, 4.12.3, 4.13.0 11.02.2023 SB2023021103
SB2023021109
SB2023021561
and 88 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
4.11.7, 4.12.2 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
4.11.7, 4.12.2 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
4.11.7, 4.12.2 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
4.11.7, 4.12.2 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71379 - Incorrect Regular Expression
CVE-2022-40897
CWE-185 Medium
No
No
4.11.7, 4.12.1, 4.12.2, 4.13.0 20.01.2023 SB2023012008
SB2023012015
SB2023012016
and 99 more
#VU71180 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-23539
CWE-327 Medium
No
No
4.12.3 16.01.2023 SB2023011632
SB2023011633
SB2023020322
and 16 more
#VU70461 - Improper Privilege Management
CVE-2022-4415
CWE-269 Low
No
No
4.11.7, 4.12.1, 4.12.2, 4.13.0 21.12.2022 SB2022122140
SB2022122735
SB2022122816
and 70 more
#VU69675 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24999
CWE-94 Medium
Available
No
4.12.3 29.11.2022 SB2022112910
SB2022112911
SB2022112943
and 49 more
#VU69582 - NULL Pointer Dereference
CVE-2022-36227
CWE-476 Low
No
No
4.11.9, 4.12.3, 4.12.4, 4.13.0 24.11.2022 SB2022112432
SB2022112437
SB2022112438
and 77 more
#VU69392 - Resource exhaustion
CVE-2022-45061
CWE-400 Medium
No
No
4.11.7, 4.12.1, 4.12.2, 4.13.0 16.11.2022 SB2022111650
SB2022112824
SB2022112856
and 125 more
#VU67760 - Type conversion
CVE-2020-10735
CWE-704 Medium
No
No
4.11.7, 4.12.1, 4.12.2, 4.13.0 29.09.2022 SB2022092968
SB2022092970
SB2022093032
and 86 more
#VU67591 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-28861
CWE-601 Low
No
No
4.11.7, 4.12.1, 4.12.2, 4.13.0 22.09.2022 SB2022092243
SB2022092244
SB2022093032
and 76 more
#VU67555 - Incorrect Regular Expression
CVE-2022-40023
CWE-185 Medium
No
No
4.11.9, 4.12.3, 4.12.4, 4.13.0 21.09.2022 SB2022092139
SB2022092141
SB2022102426
and 20 more
#VU67534 - Permissions, Privileges, and Access Controls
CVE-2022-40186
CWE-264 Low
No
No
4.11.7 21.09.2022 SB2022092124
SB2022112521
SB2023042647


Showing elements 281 - 300 out of 476