Known vulnerabilities in openstack-ironic (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:openstack-ironic_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 86
Public exploits: 6
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openstack-ironic (Red Hat package) openstack-ironic (Red Hat package) is affected by 86 known vulnerabilities: 5 high, 55 medium, 26 low Critical High Medium Low

Vulnerabilities (86)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
CWE-367 Low
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 51 more
#VU140599 - Resource exhaustion
CVE-2026-32280
CWE-400 Medium
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 75 more
#VU136680 - Dependency on Vulnerable Third-Party Component
CVE-2026-32283
CWE-1395 Medium
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 02.07.2026 SB2026070218
SB2026070239
SB2026070240
and 63 more
#VU124118 - Improper input validation
CVE-2026-25679
CWE-20 Medium
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 19.03.2026 SB2026031903
SB2026031904
SB2026031905
and 136 more
#VU124034 - Resource exhaustion
CVE-2025-61726
CWE-400 Medium
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 145 more
#VU123129 - Improper Certificate Validation
CVE-2025-68121
CWE-295 High
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 23.02.2026 SB2026022333
SB2026030334
SB2026030343
and 118 more
#VU122995 - Allocation of Resources Without Limits or Throttling
CVE-2026-24708
CWE-770 Low
No
No
17.1.1-17.1.20260721220909.c31db88.el9ost 17.02.2026 SB2026021762
SB2026021847
SB2026022004
and 2 more
#VU98817 - UNIX Symbolic Link (Symlink) Following
CVE-2024-9676
CWE-61 Low
No
No
21.0.1-0.20240913135525.114badc.el9 18.10.2024 SB2024101822
SB2024101823
SB2024101824
and 54 more
#VU98141 - Improper input validation
CVE-2024-9341
CWE-20 Low
No
No
21.0.1-0.20240913135525.114badc.el9 08.10.2024 SB2024100842
SB2024100843
SB2024100848
and 44 more
#VU98123 - Improper Validation of Integrity Check Value
CVE-2024-47211
CWE-354 Medium
No
No
17.1.1-17.1.20241122190825.c31db88.el9ost, 21.4.5-18.0.20241207142602.9213ccd.el9ost 08.10.2024 SB2024100260
SB2024102305
SB2024103012
and 2 more
#VU97965 - Improper Access Control
CVE-2024-44082
CWE-284 Low
No
No
13.0.8-2.20230713045150.d10fd5c.el8ost, 17.1.1-17.1.20240917210749.c31db88.el9ost, 21.0.1-0.20240913135525.114badc.el9, 21.3.1-0.20240911165036.c0d61d0.el9 02.10.2024 SB2024100260
SB2024100261
SB2024100262
and 10 more
#VU97217 - Resource exhaustion
CVE-2024-34158
CWE-400 Medium
No
No
21.0.1-0.20240913135525.114badc.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 76 more
#VU97216 - Resource exhaustion
CVE-2024-34156
CWE-400 Medium
No
No
21.0.1-0.20240913135525.114badc.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 143 more
#VU97215 - Resource exhaustion
CVE-2024-34155
CWE-400 Medium
No
No
21.0.1-0.20240913135525.114badc.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 81 more
#VU96055 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-42353
CWE-601 Low
No
No
21.3.1-0.20240911165036.c0d61d0.el9 15.08.2024 SB2024081552
SB2024081555
SB2024081556
and 44 more
#VU89685 - Improper Validation of Integrity Check Value
CVE-2024-3727
CWE-354 Medium
No
No
21.3.1-0.20240911165036.c0d61d0.el9 21.05.2024 SB2024052112
SB2024052116
SB2024052117
and 68 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
23.1.1-0.20240405121030.2c16b52.el9 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
21.3.1-0.20231106145533.e53dc4f.el9 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
21.3.1-0.20231106145533.e53dc4f.el9 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 652 more
#VU75790 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-24539
CWE-79 Medium
No
No
21.3.1-0.20230706125653.c8f8157.el9 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 75 more


Showing elements 1 - 20 out of 86