Known vulnerabilities in OpenShift Developer Tools and Services - page 3

Software CPE: cpe:2.3:a:red_hat:openshift_developer_tools_and_services:*:*:*:*:*:*:*:*
Total vulnerabilities: 94
Public exploits: 10
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Developer Tools and Services OpenShift Developer Tools and Services is affected by 94 known vulnerabilities: 27 high, 40 medium, 27 low Critical High Medium Low

Vulnerabilities (94)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
- 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU75915 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-2491
CWE-78 High
No
No
- 09.05.2023 SB20230509106
SB2023051666
SB2023042426
and 17 more
#VU75486 - Improper input validation
CVE-2023-29007
CWE-20 Low
Available
No
- 25.04.2023 SB2023042553
SB2023042610
SB2023042629
and 48 more
#VU75484 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-25652
CWE-59 Low
No
No
- 25.04.2023 SB2023042553
SB2023042610
SB2023042629
and 48 more
#VU73196 - Incorrect Default Permissions
CVE-2023-27903
CWE-276 Low
No
No
- 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 9 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
- 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU72438 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25762
CWE-79 Low
No
No
- 21.02.2023 SB2023022118
SB2023042646
SB2023051806
and 9 more
#VU72437 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25761
CWE-79 Low
No
No
- 21.02.2023 SB2023022116
SB2023042646
SB2023051806
and 9 more
#VU72246 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-22490
CWE-59 Low
No
No
- 15.02.2023 SB2023021529
SB2023021528
SB2023021533
and 31 more
#VU72245 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-23946
CWE-59 Medium
No
No
- 15.02.2023 SB2023021529
SB2023021528
SB2023021533
and 28 more
#VU72125 - Inadequate Encryption Strength
CVE-2023-0361
CWE-326 Medium
No
No
- 11.02.2023 SB2023021103
SB2023021109
SB2023021561
and 88 more
#VU71499 - Permissions, Privileges, and Access Controls
CVE-2023-24422
CWE-264 Medium
No
No
- 25.01.2023 SB2023012504
SB2023041270
SB2023041272
and 14 more
#VU70530 - Deserialization of Untrusted Data
CVE-2022-45047
CWE-502 High
Available
No
- 28.12.2022 SB2022122828
SB2022122920
SB2023011148
and 49 more
#VU68601 - Cross-Site Request Forgery (CSRF)
CVE-2022-43408
CWE-352 Low
No
No
- 24.10.2022 SB2022102418
SB2023020889
SB2023022307
and 4 more
#VU68600 - Cross-Site Request Forgery (CSRF)
CVE-2022-43407
CWE-352 Low
No
No
- 24.10.2022 SB2022102419
SB2023020889
SB2023022307
and 4 more
#VU68598 - Protection Mechanism Failure
CVE-2022-43405
CWE-693 Medium
No
No
- 24.10.2022 SB2022102422
SB2023020889
SB2023022307
and 4 more
#VU68390 - Resource exhaustion
CVE-2022-41715
CWE-400 Medium
No
No
- 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 113 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Available
Exploited
- 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU67665 - Resource exhaustion
CVE-2022-25857
CWE-400 Medium
No
No
- 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 83 more
#VU62608 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-29599
CWE-78 High
No
No
- 26.04.2022 SB2022042627
SB2022042724
SB2022050234
and 29 more


Showing elements 41 - 60 out of 94