Known vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) - page 4

Software CPE: cpe:2.3:a:red_hat:openshift_container_storage:*:*:*:*:*:*:*:*
Total vulnerabilities: 476
Public exploits: 35
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Data Foundation (formerly OpenShift Container Storage) OpenShift Data Foundation (formerly OpenShift Container Storage) is affected by 476 known vulnerabilities: 1 critical, 90 high, 246 medium, 139 low Critical High Medium Low

Vulnerabilities (476)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103771 - Improper Authentication
CVE-2024-12797
CWE-287 Medium
No
No
4 11.02.2025 SB2025021187
SB20250211108
SB20250211159
and 59 more
#VU103502 - Use After Free
CVE-2022-49043
CWE-416 Medium
No
No
4 03.02.2025 SB2025020327
SB2025020330
SB2025020353
and 60 more
#VU102730 - Use of Uninitialized Variable
CVE-2024-12085
CWE-457 Medium
No
No
4.16.6, 4.17.3 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 92 more
#VU102463 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-55565
CWE-835 Medium
No
No
4.16.5, 4.17.2, 4.18.0 08.01.2025 SB2025010849
SB2025010851
SB2025010853
and 45 more
#VU101895 - Inefficient Regular Expression Complexity
CVE-2024-52798
CWE-1333 Low
No
No
4.16.6, 4.17.3 23.12.2024 SB2024122305
SB2024122309
SB2025011306
and 45 more
#VU101868 - Resource exhaustion
CVE-2024-45338
CWE-400 Medium
No
No
4, 4.14.18, 4.15.14, 4.16.6, 4.17.3, 4.17.7, 4.18.0 19.12.2024 SB2024121932
SB2024123101
SB2025010619
and 137 more
#VU100921 - Incorrect Regular Expression
CVE-2024-21538
CWE-185 Medium
No
No
4.14.18, 4.15.9, 4.15.14, 4.16.4, 4.16.5, 4.17.1, 4.17.2, 4.18.0 26.11.2024 SB2024112627
SB2024112629
SB2024120325
and 67 more
#VU100516 - Improper input validation
CVE-2024-11168
CWE-20 Medium
No
No
4.14.13, 4.15.9, 4.16.5, 4.17.2 15.11.2024 SB2024111507
SB2024111526
SB2024111527
and 76 more
#VU99556 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2024-48910
CWE-1321 Medium
No
No
4.14.18, 4.15.14, 4.16.5, 4.17.2 31.10.2024 SB2024103154
SB2024111356
SB2024112007
and 15 more
#VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-9287
CWE-78 Low
No
No
4.14.13, 4.15.9, 4.16.5, 4.17.2 28.10.2024 SB2024102836
SB2024102838
SB20241101111
and 117 more
#VU98132 - Inefficient Regular Expression Complexity
CVE-2024-45296
CWE-1333 Low
No
No
4.14.13, 4.15.9, 4.16.5, 4.17.0 08.10.2024 SB2024100822
SB2024100823
SB2024100826
and 87 more
#VU98131 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43800
CWE-79 Medium
No
No
4.14.13, 4.15.9, 4.16.3, 4.16.5, 4.17.0, 4.17.2 08.10.2024 SB2024100821
SB2024100824
SB2024100825
and 48 more
#VU97768 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43799
CWE-79 Low
No
No
4.14.13, 4.15.9, 4.16.3, 4.16.5, 4.17.0, 4.17.2 30.09.2024 SB2024093022
SB2024100824
SB2024100825
and 50 more
#VU97209 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43796
CWE-79 Medium
No
No
4.14.13, 4.15.9, 4.16.3, 4.16.5, 4.17.0, 4.17.2 12.09.2024 SB2024091250
SB2024091251
SB2024091252
and 52 more
#VU93850 - Resource exhaustion
CVE-2024-24791
CWE-400 Medium
No
No
4.16.5 07.07.2024 SB2024070727
SB2024070728
SB2024070729
and 86 more
#VU84457 - Improper input validation
CVE-2023-26364
CWE-20 Medium
No
No
4.14.13, 4.15.9, 4.16.5, 4.17.0 15.12.2023 SB2023121517
SB2024042435
SB2024042436
and 8 more
#VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-26136
CWE-1321 High
No
No
4.14.13, 4.15.9, 4.16.5, 4.17.0 04.09.2023 SB2023090411
SB2023090423
SB2023090816
and 42 more
#VU63060 - Heap-based Buffer Overflow
CVE-2021-3903
CWE-122 High
No
No
4.14.13, 4.15.9, 4.16.4, 4.17.1 11.05.2022 SB2022051173
SB2021111514
SB2022062022
and 39 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
4 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU19178 - Out-of-bounds write
CVE-2019-12900
CWE-787 High
No
No
4 15.07.2019 SB2019071503
SB2019072101
SB2019080907
and 85 more


Showing elements 61 - 80 out of 476