Known vulnerabilities in OpenShift Service Mesh - page 9

Software CPE: cpe:2.3:a:red_hat:openshift_service_mesh:*:*:*:*:*:*:*:*
Total vulnerabilities: 273
Public exploits: 17
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Service Mesh OpenShift Service Mesh is affected by 273 known vulnerabilities: 47 high, 157 medium, 69 low Critical High Medium Low

Vulnerabilities (273)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75791 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24540
CWE-94 Medium
No
No
2.4.0 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 81 more
#VU74181 - Improper input validation
CVE-2021-20329
CWE-20 Medium
No
No
2.2.7 29.03.2023 SB2021061037
SB2023032956
SB2023032959
and 10 more
#VU72432 - Heap-based Buffer Overflow
CVE-2022-48303
CWE-122 High
No
No
2.2.11, 2.3.2, 2.3.8, 2.4.4, 2.5.2 21.02.2023 SB2023022105
SB2023022111
SB2023022112
and 72 more
#VU72337 - Allocation of Resources Without Limits or Throttling
CVE-2023-23916
CWE-770 Medium
No
No
2.3.2 16.02.2023 SB2023021668
SB2023021670
SB2023021671
and 89 more
#VU72132 - Improper Authentication
CVE-2022-39229
CWE-287 Low
No
No
2.2.7, 2.4.0 12.02.2023 SB2023021201
SB2023021202
SB2023021203
and 13 more
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
2.2.7, 2.2.8, 2.3.5, 2.4.1 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
2.2.7, 2.2.8, 2.3.5, 2.4.1 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71365 - Configuration
CVE-2022-3466
CWE-16 Low
No
No
2.4.0 19.01.2023 SB2023011939
SB2023020908
SB2023032315
and 4 more
#VU71364 - Improper Access Control
CVE-2022-3162
CWE-284 Low
No
No
2.4.0 19.01.2023 SB2023011938
SB2023011939
SB2023020908
and 17 more
#VU71362 - Protection Mechanism Failure
CVE-2022-3259
CWE-693 Low
No
No
2.4.0 19.01.2023 SB2023011939
SB2023020908
SB2023032315
and 8 more
#VU71361 - Resource exhaustion
CVE-2021-4235
CWE-400 Medium
No
No
2.4.0 19.01.2023 SB2023011937
SB2023011939
SB2023020869
and 13 more
#VU69675 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24999
CWE-94 Medium
Available
No
2.2.7 29.11.2022 SB2022112910
SB2022112911
SB2022112943
and 49 more
#VU69407 - Resource exhaustion
CVE-2022-3204
CWE-400 Medium
No
No
2.4.0 18.11.2022 SB2022111805
SB2022111806
SB2022111808
and 19 more
#VU67974 - Incorrect Regular Expression
CVE-2022-25858
CWE-185 Medium
No
No
2.2.7 06.10.2022 SB2022100649
SB2022100650
SB2022110245
and 8 more
#VU67969 - Reachable Assertion
CVE-2022-42010
CWE-617 Low
No
No
2.3.1, 2.3.2 06.10.2022 SB2022100645
SB2022100708
SB2022102733
and 58 more
#VU67556 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-32190
CWE-22 Medium
No
No
2.4.0 21.09.2022 SB2022091520
SB2022092146
SB2022092946
and 33 more
#VU67554 - Server-Side Request Forgery (SSRF)
CVE-2022-3172
CWE-918 Medium
No
No
2.4.0 21.09.2022 SB2022092138
SB2022102614
SB2023011939
and 23 more
#VU67545 - Resource Management Errors
CVE-2022-2795
CWE-399 Medium
No
No
2.4.0, 2.4.8, 2.5.2 21.09.2022 SB2022092131
SB2022092140
SB2022092143
and 71 more
#VU66817 - Improper Access Control
CVE-2022-2995
CWE-284 Low
No
No
2.4.0 30.08.2022 SB2022083001
SB2023011939
SB2023020908
and 11 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
2.2.7 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more


Showing elements 161 - 180 out of 273