Known vulnerabilities in OpenShift Logging - page 4

Software CPE: cpe:2.3:a:red_hat:openshift_logging:*:*:*:*:*:*:*:*
Total vulnerabilities: 810
Public exploits: 50
Known exploited (KEV): 10
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Logging OpenShift Logging is affected by 810 known vulnerabilities: 2 critical, 100 high, 218 medium, 490 low Critical High Medium Low

Vulnerabilities (810)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU102730 - Use of Uninitialized Variable
CVE-2024-12085
CWE-457 Medium
No
No
5.8.17, 5.9.11 14.01.2025 SB2025011495
SB2025011504
SB2025011530
and 92 more
#VU102463 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-55565
CWE-835 Medium
No
No
5.9.10 08.01.2025 SB2025010849
SB2025010851
SB2025010853
and 45 more
#VU101111 - Divide By Zero
CVE-2024-53122
CWE-369 Low
No
No
5.8.17 03.12.2024 SB2024120317
SB2025010804
SB2025010805
and 65 more
#VU100997 - Insecure Storage of Sensitive Information
CVE-2024-10041
CWE-922 Low
No
No
5.6.27 27.11.2024 SB2024112540
SB2024112747
SB2024112748
and 38 more
#VU100912 - Improper Authentication
CVE-2024-10963
CWE-287 Medium
No
No
5.6.27, 5.8.16, 5.9.10 25.11.2024 SB2024112540
SB2024112541
SB2024112542
and 56 more
#VU100516 - Improper input validation
CVE-2024-11168
CWE-20 Medium
No
No
5.6.27, 5.8.17 15.11.2024 SB2024111507
SB2024111526
SB2024111527
and 76 more
#VU100173 - Out-of-bounds read
CVE-2024-50262
CWE-125 Low
No
No
5.8.17 10.11.2024 SB2024111017
SB2024112401
SB2024112950
and 56 more
#VU99614 - Improper input validation
CVE-2024-50602
CWE-20 Medium
No
No
5.6.27, 5.8.16, 5.9.10 01.11.2024 SB2024110155
SB2024110182
SB2024110534
and 98 more
#VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-9287
CWE-78 Low
No
No
5.6.27, 5.8.17 28.10.2024 SB2024102836
SB2024102838
SB20241101111
and 117 more
#VU99261 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-47875
CWE-79 Medium
No
No
5.6.27, 5.8.16 22.10.2024 SB20241022382
SB20241022383
SB20241022392
and 27 more
#VU98142 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-47220
CWE-444 Medium
No
No
5.9.11 08.10.2024 SB2024100844
SB2024100847
SB2024100853
and 16 more
#VU94063 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2024-3596
CWE-327 Medium
Available
No
5.8.16, 5.8.17, 5.8.19, 5.8.20, 5.9.10, 5.9.14 10.07.2024 SB2024071018
SB2024071019
SB2024071020
and 114 more
#VU90156 - Security Features
CVE-2024-35195
CWE-254 Low
No
No
5.6.27 31.05.2024 SB2024053174
SB2024053188
SB2024053192
and 117 more
#VU89624 - Resource Management Errors
CVE-2024-4603
CWE-399 Low
No
No
5.8.16, 5.8.17, 5.8.19, 5.8.20, 5.9.10, 5.9.14 17.05.2024 SB2024051715
SB2024052732
SB2024060735
and 65 more
#VU88211 - Resource exhaustion
CVE-2024-2511
CWE-400 Medium
No
No
5.8.16, 5.8.17, 5.8.19, 5.8.20, 5.9.10, 5.9.14 08.04.2024 SB2024040853
SB2024042960
SB2024051069
and 91 more
#VU88151 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-38709
CWE-113 Medium
No
No
5.8.16 04.04.2024 SB2024040458
SB2024040502
SB2024040903
and 62 more
#VU87339 - Information Exposure Through Timing Discrepancy
CVE-2024-2236
CWE-208 Medium
No
No
5.8.16, 5.8.17, 5.8.19, 5.8.20, 5.9.10, 5.9.14, 6.1.5 11.03.2024 SB2024031137
SB2024031141
SB2024111242
and 58 more
#VU63060 - Heap-based Buffer Overflow
CVE-2021-3903
CWE-122 High
No
No
5.8.16 11.05.2022 SB2022051173
SB2021111514
SB2022062022
and 39 more
#VU19178 - Out-of-bounds write
CVE-2019-12900
CWE-787 High
No
No
5.6.27, 5.8.17, 5.8.19, 5.8.20, 5.9.11, 5.9.14 15.07.2019 SB2019071503
SB2019072101
SB2019080907
and 85 more
#VU13471 - Heap-based Buffer Overflow
CVE-2018-12699
CWE-122 Low
No
No
5.6.27 25.06.2018 SB2018041305
SB2021123106
SB2024111503
and 8 more


Showing elements 61 - 80 out of 810