Known vulnerabilities in OpenShift Developer Tools and Services - page 2

Software CPE: cpe:2.3:a:red_hat:openshift_developer_tools_and_services:*:*:*:*:*:*:*:*
Total vulnerabilities: 94
Public exploits: 10
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Developer Tools and Services OpenShift Developer Tools and Services is affected by 94 known vulnerabilities: 27 high, 40 medium, 27 low Critical High Medium Low

Vulnerabilities (94)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85791 - Improper Access Control
CVE-2024-23899
CWE-284 Medium
No
No
- 25.01.2024 SB2024012514
SB20240611153
SB20240611154
and 1 more
#VU85790 - Missing Origin Validation in WebSockets
CVE-2024-23898
CWE-1385 High
Available
No
- 25.01.2024 SB2024012513
SB2024021214
SB2024021215
and 1 more
#VU85786 - Improper Access Control
CVE-2024-23897
CWE-284 High
Available
Exploited
- 25.01.2024 SB2024012513
SB2024021214
SB2024021215
and 6 more
#VU80791 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-40167
CWE-444 Medium
No
No
- 14.09.2023 SB2023091440
SB2023092933
SB2023101760
and 68 more
#VU79891 - Cross-Site Request Forgery (CSRF)
CVE-2023-40341
CWE-352 Low
No
No
- 23.08.2023 SB2023082325
SB2024021216
SB2024021217
#VU79888 - Exposure of sensitive information to an unauthorized actor
CVE-2023-40339
CWE-200 Low
No
No
- 23.08.2023 SB2023082323
SB2023112014
SB2024021216
and 1 more
#VU79886 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-40338
CWE-22 Low
No
No
- 23.08.2023 SB2023082322
SB2023112014
SB2024021216
and 1 more
#VU79885 - Cross-Site Request Forgery (CSRF)
CVE-2023-40337
CWE-352 Low
No
No
- 23.08.2023 SB2023082322
SB2023112014
SB2024021216
and 1 more
#VU78258 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-37947
CWE-601 Low
No
No
- 14.07.2023 SB2023071418
SB2024021216
SB2024021217
#VU78257 - Session Fixation
CVE-2023-37946
CWE-384 High
No
No
- 14.07.2023 SB2023071418
SB2024021214
SB2024021215
and 1 more
#VU77107 - Incorrect Default Permissions
CVE-2023-2976
CWE-276 Low
No
No
- 08.06.2023 SB2023060849
SB2023071712
SB2023072512
and 157 more
#VU75562 - Improper input validation
CVE-2023-20861
CWE-20 Medium
No
No
- 27.04.2023 SB2023042742
SB2023042746
SB2023042832
and 61 more
#VU75408 - Security Features
CVE-2023-20862
CWE-254 Medium
No
No
- 21.04.2023 SB2023042130
SB2023042132
SB2023053121
and 20 more
#VU75218 - Resource exhaustion
CVE-2023-26048
CWE-400 Medium
No
No
- 18.04.2023 SB2023041842
SB2023051753
SB2023060701
and 55 more
#VU75217 - Improper input validation
CVE-2023-26049
CWE-20 Low
No
No
- 18.04.2023 SB2023041842
SB2023051821
SB2023060836
and 78 more
#VU73197 - Exposure of sensitive information to an unauthorized actor
CVE-2023-27904
CWE-200 Low
No
No
- 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 10 more
#VU72076 - Incorrect Authorization
CVE-2020-7692
CWE-863 High
No
No
- 08.02.2023 SB2020070955
SB2023020889
SB2023022307
and 9 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
- 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU66065 - Resource exhaustion
CVE-2022-1962
CWE-400 Medium
No
No
- 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 73 more
#VU62492 - Origin Validation Error
CVE-2021-26291
CWE-346 High
No
No
- 22.04.2022 SB2021042333
SB2022042228
SB2022072038
and 15 more


Showing elements 21 - 40 out of 94