Known vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) - page 3

Software CPE: cpe:2.3:a:red_hat:openshift_container_storage:*:*:*:*:*:*:*:*
Total vulnerabilities: 476
Public exploits: 35
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Data Foundation (formerly OpenShift Container Storage) OpenShift Data Foundation (formerly OpenShift Container Storage) is affected by 476 known vulnerabilities: 1 critical, 90 high, 246 medium, 139 low Critical High Medium Low

Vulnerabilities (476)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU106253 - Improper input validation
CVE-2025-22870
CWE-20 Medium
Available
No
4.18.3 30.03.2025 SB2025033001
SB2025033002
SB2025033003
and 106 more
#VU105983 - Resource exhaustion
CVE-2025-30204
CWE-400 Medium
No
No
4, 4.15.14, 4.17.7, 4.18 24.03.2025 SB2025032475
SB2025032730
SB2025040333
and 97 more
#VU105946 - Use After Free
CVE-2025-24855
CWE-416 High
No
No
4, 4.17.7 21.03.2025 SB2025031964
SB2025032154
SB2025032155
and 63 more
#VU105723 - Stack-based buffer overflow
CVE-2024-8176
CWE-121 High
No
No
4, 4.14.18, 4.15.14, 4.17.7 14.03.2025 SB2025031426
SB2025031429
SB2025031430
and 105 more
#VU105715 - Out-of-bounds write
CVE-2025-27363
CWE-787 Critical
Available
Exploited
4 14.03.2025 SB2025031402
SB2025031502
SB2025031750
and 97 more
#VU105459 - Resource exhaustion
CVE-2025-22869
CWE-400 Low
No
No
4 10.03.2025 SB2025031011
SB2025031015
SB2025032557
and 108 more
#VU105450 - Resource exhaustion
CVE-2025-27144
CWE-400 Medium
No
No
4, 4.17.7 07.03.2025 SB2025030735
SB2025030736
SB2025030737
and 80 more
#VU105387 - Improper input validation
CVE-2025-27516
CWE-20 Low
No
No
4, 4.14.18, 4.15.14, 4.17.7 06.03.2025 SB2025030628
SB2025031001
SB2025031002
and 83 more
#VU104215 - Resource Management Errors
CVE-2025-0426
CWE-399 Medium
No
No
4, 4.18.0 26.02.2025 SB2025022620
SB2025022624
SB2025030776
and 4 more
#VU104117 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-1244
CWE-78 High
No
No
4, 4.18.0 21.02.2025 SB2025022110
SB2025022111
SB2025022112
and 31 more
#VU104099 - Use After Free
CVE-2024-56171
CWE-416 High
No
No
4 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
4 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104017 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2024-21528
CWE-1321 Medium
No
No
4, 4.18.0 17.02.2025 SB2025021734
SB2025021744
SB2025022530
and 2 more
#VU103687 - Memory corruption
CVE-2025-0395
CWE-119 Medium
No
No
4, 4.14.18, 4.15.14, 4.17.7 06.02.2025 SB2025020664
SB2025020667
SB2025020668
and 66 more
#VU103436 - Resource exhaustion
CVE-2024-11187
CWE-400 Medium
No
No
4, 4.18.0 29.01.2025 SB2025012962
SB2025012964
SB2025012965
and 83 more
#VU101777 - Improper Authorization
CVE-2024-45337
CWE-285 Medium
Available
No
4, 4.18.0 13.12.2024 SB2024121332
SB2024121333
SB2024121334
and 93 more
#VU101027 - Error Handling
CVE-2024-21536
CWE-388 Medium
No
No
4, 4.14.18, 4.15.14, 4.17.7 28.11.2024 SB2024112825
SB2024112826
SB2024120211
and 22 more
#VU98048 - Improper Authentication
CVE-2024-47191
CWE-287 Low
No
No
4, 4.14.18, 4.15.14, 4.18.3 05.10.2024 SB2024100508
SB2024100513
SB2024100514
and 19 more
#VU85240 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-11831
CWE-79 Medium
No
No
4, 4.14.18, 4.15.14, 4.17.7 09.01.2024 SB2024010997
SB2025021411
SB2025021412
and 17 more
#VU81307 - Improper input validation
CVE-2023-44270
CWE-20 Low
No
No
4, 4.18.0 02.10.2023 SB2023100210
SB2023111710
SB2023112080
and 28 more


Showing elements 41 - 60 out of 476