Known vulnerabilities in OpenShift Service Mesh - page 3

Software CPE: cpe:2.3:a:red_hat:openshift_service_mesh:*:*:*:*:*:*:*:*
Total vulnerabilities: 273
Public exploits: 17
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Service Mesh OpenShift Service Mesh is affected by 273 known vulnerabilities: 47 high, 157 medium, 69 low Critical High Medium Low

Vulnerabilities (273)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU98131 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43800
CWE-79 Medium
No
No
2.4.11, 2.5.5, 2.6.2 08.10.2024 SB2024100821
SB2024100824
SB2024100825
and 48 more
#VU97768 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43799
CWE-79 Low
No
No
2.4.11, 2.5.5, 2.6.2 30.09.2024 SB2024093022
SB2024100824
SB2024100825
and 50 more
#VU96899 - Integer overflow
CVE-2024-45492
CWE-190 High
No
No
2.4.11, 2.5.5, 2.5.6, 2.6.2 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 108 more
#VU96898 - Integer overflow
CVE-2024-45491
CWE-190 High
No
No
2.4.11, 2.5.5, 2.5.6, 2.6.2 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 106 more
#VU96897 - Buffer Underwrite ('Buffer Underflow')
CVE-2024-45490
CWE-124 High
No
No
2.4.11, 2.5.5, 2.5.6, 2.6.2 05.09.2024 SB20240905100
SB20240905101
SB20240905102
and 113 more
#VU96745 - Incorrect Regular Expression
CVE-2024-6232
CWE-185 Medium
No
No
2.4.11, 2.5.5, 2.5.6, 2.6.2 03.09.2024 SB2024090377
SB2024090927
SB2024091048
and 145 more
#VU96642 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-43788
CWE-79 Low
No
No
2.4.11, 2.5.5, 2.6.2 30.08.2024 SB2024083026
SB2024100824
SB2024100825
and 21 more
#VU95571 - Command injection
CVE-2024-6923
CWE-77 Medium
No
No
2.4.11, 2.5.5, 2.5.6, 2.6.2 08.08.2024 SB2024080861
SB2024080862
SB2024080863
and 144 more
#VU95339 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-6345
CWE-94 High
No
No
2.4.11, 2.5.5, 2.6.2 05.08.2024 SB2024080590
SB2024080593
SB2024080594
and 160 more
#VU95157 - Incorrect Provision of Specified Functionality
CVE-2024-4032
CWE-684 Medium
No
No
2.4.11, 2.5.5, 2.5.6, 2.6.2 02.08.2024 SB2024080203
SB2024080207
SB2024080209
and 101 more
#VU93118 - Use of Potentially Dangerous Function
CVE-2024-39331
CWE-676 High
No
No
2.5.5, 2.6.2 24.06.2024 SB2024062429
SB2024062430
SB2024062431
and 46 more
#VU91152 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-32976
CWE-835 Medium
No
No
2.4.11, 2.5.5 05.06.2024 SB2024060518
SB2024060519
SB2024070220
and 2 more
#VU88855 - Incorrect Check of Function Return Value
CVE-2024-32475
CWE-253 Medium
No
No
2.4.11, 2.5.5 19.04.2024 SB2024041931
SB2024052109
SB2024070220
and 2 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
2.4.8 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU87850 - Missing Release of Resource after Effective Lifetime
CVE-2024-2398
CWE-772 Medium
No
No
2.4.11, 2.5.5, 2.6.2 27.03.2024 SB2024032713
SB2024032740
SB2024032744
and 106 more
#VU80421 - Out-of-bounds read
CVE-2022-48554
CWE-125 Low
No
No
2.4.8, 2.5.2 05.09.2023 SB2023090535
SB2023090536
SB2023091257
and 52 more
#VU75482 - Integer overflow
CVE-2022-48468
CWE-190 High
No
No
2.5.2 25.04.2023 SB2022072825
SB2023042551
SB2023050992
and 50 more
#VU71559 - NULL Pointer Dereference
CVE-2022-47024
CWE-476 Low
No
No
2.5.2 26.01.2023 SB2023012623
SB2023013121
SB2023022848
and 16 more
#VU71529 - Resource exhaustion
CVE-2022-3094
CWE-400 Medium
No
No
2.4.8, 2.5.2 25.01.2023 SB2023012556
SB2023012559
SB2023012602
and 47 more
#VU61422 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-25220
CWE-350 Medium
No
No
2.4.8, 2.5.2 17.03.2022 SB2022031701
SB2022031719
SB2022031725
and 57 more


Showing elements 41 - 60 out of 273