Known vulnerabilities in openstack-ironic (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:openstack-ironic_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 79
Public exploits: 6
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openstack-ironic (Red Hat package) openstack-ironic (Red Hat package) is affected by 79 known vulnerabilities: 4 high, 51 medium, 24 low Critical High Medium Low

Vulnerabilities (79)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU98817 - UNIX Symbolic Link (Symlink) Following
CVE-2024-9676
CWE-61 Low
No
No
21.0.1-0.20240913135525.114badc.el9 18.10.2024 SB2024101822
SB2024101823
SB2024101824
and 54 more
#VU98141 - Improper input validation
CVE-2024-9341
CWE-20 Low
No
No
21.0.1-0.20240913135525.114badc.el9 08.10.2024 SB2024100842
SB2024100843
SB2024100848
and 44 more
#VU98123 - Improper Validation of Integrity Check Value
CVE-2024-47211
CWE-354 Medium
No
No
17.1.1-17.1.20241122190825.c31db88.el9ost, 21.4.5-18.0.20241207142602.9213ccd.el9ost 08.10.2024 SB2024100260
SB2024102305
SB2024103012
and 2 more
#VU97965 - Improper Access Control
CVE-2024-44082
CWE-284 Low
No
No
13.0.8-2.20230713045150.d10fd5c.el8ost, 17.1.1-17.1.20240917210749.c31db88.el9ost, 21.0.1-0.20240913135525.114badc.el9, 21.3.1-0.20240911165036.c0d61d0.el9 02.10.2024 SB2024100260
SB2024100261
SB2024100262
and 10 more
#VU97217 - Resource exhaustion
CVE-2024-34158
CWE-400 Medium
No
No
21.0.1-0.20240913135525.114badc.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 76 more
#VU97216 - Resource exhaustion
CVE-2024-34156
CWE-400 Medium
No
No
21.0.1-0.20240913135525.114badc.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 143 more
#VU97215 - Resource exhaustion
CVE-2024-34155
CWE-400 Medium
No
No
21.0.1-0.20240913135525.114badc.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 81 more
#VU96055 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-42353
CWE-601 Low
No
No
21.3.1-0.20240911165036.c0d61d0.el9 15.08.2024 SB2024081552
SB2024081555
SB2024081556
and 44 more
#VU89685 - Improper Validation of Integrity Check Value
CVE-2024-3727
CWE-354 Medium
No
No
21.3.1-0.20240911165036.c0d61d0.el9 21.05.2024 SB2024052112
SB2024052116
SB2024052117
and 68 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
23.1.1-0.20240405121030.2c16b52.el9 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
21.3.1-0.20231106145533.e53dc4f.el9 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
21.3.1-0.20231106145533.e53dc4f.el9 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU78481 - Permissions, Privileges, and Access Controls
CVE-2023-1260
CWE-264 Low
No
No
21.3.1-0.20230706125653.c8f8157.el9 21.07.2023 SB2023072111
SB2023072112
SB2023072113
and 6 more
#VU78005 - Inadequate Encryption Strength
CVE-2023-3089
CWE-326 Medium
No
No
21.3.1-0.20230706125653.c8f8157.el9 06.07.2023 SB2023070602
SB2023070603
SB2023070604
and 34 more
#VU75790 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-24539
CWE-79 Medium
No
No
21.3.1-0.20230706125653.c8f8157.el9 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 75 more
#VU74574 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24538
CWE-94 High
No
No
21.3.1-0.20230706125653.c8f8157.el9 06.04.2023 SB2023040668
SB2023040678
SB2023040679
and 85 more
#VU74573 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-24537
CWE-835 Medium
No
No
21.3.1-0.20230706125653.c8f8157.el9 06.04.2023 SB2023040668
SB2023040678
SB2023040679
and 87 more
#VU74572 - Resource Management Errors
CVE-2023-24536
CWE-399 Medium
No
No
21.3.1-0.20230706125653.c8f8157.el9 06.04.2023 SB2023040668
SB2023040678
SB2023040679
and 80 more
#VU74571 - Resource exhaustion
CVE-2023-24534
CWE-400 Medium
No
No
21.3.1-0.20230706125653.c8f8157.el9 06.04.2023 SB2023040668
SB2023040678
SB2023040679
and 85 more
#VU74190 - Improper Access Control
CVE-2023-27561
CWE-284 Low
No
No
21.3.1-0.20230706125653.c8f8157.el9 30.03.2023 SB2023033025
SB2023040327
SB2023042614
and 40 more


Showing elements 1 - 20 out of 79