Known vulnerabilities in OpenShift Service Mesh 2.3.0 - page 4

Version: 2.3.0
Software CPE: cpe:2.3:a:red_hat:openshift_service_mesh:*:*:*:*:*:*:*:*
Total vulnerabilities: 84
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting OpenShift Service Mesh version 2.3.0 OpenShift Service Mesh 2.3.0 is affected by 84 vulnerabilities: 19 high, 48 medium, 17 low Critical High Medium Low

Vulnerabilities (84)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68387 - Resource Management Errors
CVE-2022-2879
CWE-399 Medium
No
No
2.3.1, 2.4.0 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 78 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Public exploit available
No
2.3.1 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU66070 - Resource exhaustion
CVE-2022-30633
CWE-400 Medium
No
No
2.2.2, 2.3.1 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 72 more
#VU66069 - Resource exhaustion
CVE-2022-28131
CWE-400 Medium
No
No
2.2.2, 2.3.1 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 72 more
#VU66068 - Resource exhaustion
CVE-2022-30635
CWE-400 Medium
No
No
2.2.2, 2.3.1 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66067 - Resource exhaustion
CVE-2022-30632
CWE-400 Medium
No
No
2.2.2, 2.3.1 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 79 more
#VU66066 - Security Features
CVE-2022-32148
CWE-254 Medium
No
No
2.3.1, 2.4.0 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66063 - Resource exhaustion
CVE-2022-30630
CWE-400 Medium
No
No
2.2.2, 2.3.1 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 79 more
#VU66062 - Resource exhaustion
CVE-2022-30631
CWE-400 Medium
No
No
2.3.1, 2.4.0 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 100 more
#VU64399 - Cross-Site Request Forgery (CSRF)
CVE-2022-21703
CWE-352 Medium
No
No
2.3.1 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
2.3.1 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64394 - Authorization Bypass Through User-Controlled Key
CVE-2022-21713
CWE-639 Low
No
No
2.3.1 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 13 more
#VU63822 - Heap-based Buffer Overflow
CVE-2022-30293
CWE-122 High
No
No
2.3.1 30.05.2022 SB2022053014
SB2022053015
SB2022060119
and 30 more
#VU63280 - Use After Free
CVE-2022-26709
CWE-416 High
No
No
2.3.1 16.05.2022 SB2022051701
SB2022051704
SB2022051705
and 36 more
#VU63281 - Use After Free
CVE-2022-26710
CWE-416 High
No
No
2.3.1 16.05.2022 SB2022051701
SB2022051705
SB2022051706
and 34 more
#VU63282 - Use After Free
CVE-2022-26717
CWE-416 High
Public exploit available
No
2.3.1 16.05.2022 SB2022051701
SB2022051704
SB2022051705
and 37 more
#VU63283 - Memory corruption
CVE-2022-26716
CWE-119 High
No
No
2.3.1 16.05.2022 SB2022051701
SB2022051704
SB2022051705
and 36 more
#VU63284 - Memory corruption
CVE-2022-26719
CWE-119 High
No
No
2.3.1 16.05.2022 SB2022051701
SB2022051704
SB2022051705
and 34 more
#VU61335 - Use After Free
CVE-2022-22624
CWE-416 High
No
No
2.3.1 14.03.2022 SB2022031433
SB2022031436
SB2022031437
and 32 more
#VU61333 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22662
CWE-200 Medium
No
No
2.3.1 14.03.2022 SB2022031433
SB2022031434
SB2022031435
and 35 more


Showing elements 61 - 80 out of 84