Known vulnerabilities in python-pulpcore (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python-pulpcore (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python-pulpcore_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
95
Public exploits:
7
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.63.21-2.el9pc
3.49.39-2.el8pc
3.49.39-2.el9pc
3.63.21-1.el9pc
3.49.39-1.el8pc
3.49.39-1.el9pc
3.63.11-1.el9pc
3.39.25-1.el8pc
3.28.37-1.el9ap
3.49.33-1.el8pc
3.49.33-1.el9pc
3.49.22-1.el8ui
3.28.36-1.el9ap
3.49.28-1.el8pc
3.49.28-1.el9pc
3.49.19-1.el8pc
3.49.19-1.el9pc
3.39.21-1.el8pc
3.28.32-1.el9ap
3.28.31-1.el9ap
3.28.27-1.el9ap
3.39.8-2.el8pc
3.39.11-1.el8ui
3.28.24-1.el9ap
3.22.22-2.el8pc
3.28.23-1.el9ap
3.22.19-1.el8pc
3.22.15-2.el8pc
3.21.18-1.el8pc
3.21.9-1.el8pc
3.11.2-2.el8pc
3.18.16-1.el8pc
3.16.15-1.el8pc
3.21.0-1.0.1.el8ui
3.16.9-1.el8pc
3.14.8-2.el7pc
3.18.11-1.el8pc
3.15.9-2.el8pc
3.17.6-3.el8ui
3.14.12-1.el7pc
3.7.6-1.el7pc
3.7.3-2.el7pc
Vulnerabilities (95)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU105796 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-27610 |
CWE-22 | Medium | 3.39.25-1.el8pc, 3.63.11-1.el9pc | 17.03.2025 |
SB2025031756 SB20250317118 SB20250317119 and 15 more |
||
| #VU105689 - Improper Control of Generation of Code ('Code Injection') CVE-2025-27407 |
CWE-94 | High | 3.39.25-1.el8pc, 3.63.11-1.el9pc | 13.03.2025 |
SB2025031315 SB2025031316 SB2025040330 and 3 more |
||
| #VU105387 - Improper input validation CVE-2025-27516 |
CWE-20 | Low | 3.28.37-1.el9ap | 06.03.2025 |
SB2025030628 SB2025031001 SB2025031002 and 83 more |
||
| #VU103000 - Improper input validation CVE-2024-56374 |
CWE-20 | Medium | 3.49.33-1.el8pc, 3.49.33-1.el9pc, 3.63.11-1.el9pc | 20.01.2025 |
SB2025012005 SB2025012029 SB2025012030 and 11 more |
||
| #VU101972 - Security Features CVE-2024-56326 |
CWE-254 | Low | 3.28.36-1.el9ap, 3.49.33-1.el8pc, 3.49.33-1.el9pc, 3.63.11-1.el9pc | 27.12.2024 |
SB2024122789 SB2024122790 SB2024122791 and 78 more |
||
| #VU101971 - Security Features CVE-2024-56201 |
CWE-254 | Low | 3.28.36-1.el9ap, 3.39.25-1.el8pc | 27.12.2024 |
SB2024122789 SB2025010203 SB2025010322 and 62 more |
||
| #VU101276 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-53908 |
CWE-89 | High | 3.28.36-1.el9ap | 05.12.2024 |
SB2024120536 SB2024120537 SB2024120538 and 15 more |
||
| #VU99570 - Exposure of sensitive information to an unauthorized actor CVE-2024-8553 |
CWE-200 | Low | 3.49.19-1.el8pc, 3.49.19-1.el9pc | 31.10.2024 |
SB20241031110 SB2024110111 SB2024110112 and 2 more |
||
| #VU99568 - Missing release of memory after effective lifetime CVE-2024-8376 |
CWE-401 | Medium | 3.49.19-1.el8pc, 3.49.19-1.el9pc | 31.10.2024 |
SB20241031109 SB2024110111 SB2024110112 and 7 more |
||
| #VU97631 - Insecure inherited permissions CVE-2024-7143 |
CWE-277 | Medium | 3.28.32-1.el9ap | 20.09.2024 |
SB2024092030 SB2024092068 SB2025060536 and 2 more |
||
| #VU97594 - Improper Authentication CVE-2024-7923 |
CWE-287 | High | 3.49.19-1.el8pc, 3.49.19-1.el9pc | 19.09.2024 |
SB2024092064 SB2024092065 SB2024092066 and 1 more |
||
| #VU97593 - Improper Authentication CVE-2024-7012 |
CWE-287 | High | 3.49.19-1.el8pc, 3.49.19-1.el9pc | 19.09.2024 |
SB2024092064 SB2024092065 SB2024092066 and 1 more |
||
| #VU95445 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-42005 |
CWE-89 | High | 3.28.31-1.el9ap, 3.49.19-1.el8pc, 3.49.19-1.el9pc, 3.49.22-1.el8ui | 07.08.2024 |
SB2024080728 SB2024080771 SB2024080772 and 12 more |
||
| #VU95444 - Improper input validation CVE-2024-41991 |
CWE-20 | Medium | 3.28.31-1.el9ap, 3.39.21-1.el8pc, 3.49.22-1.el8ui | 07.08.2024 |
SB2024080728 SB2024080771 SB2024080772 and 12 more |
||
| #VU95443 - Improper input validation CVE-2024-41990 |
CWE-20 | Medium | 3.28.31-1.el9ap, 3.49.22-1.el8ui | 07.08.2024 |
SB2024080728 SB2024080771 SB2024080772 and 11 more |
||
| #VU92406 - Incorrect Regular Expression CVE-2024-4067 |
CWE-185 | Medium | 3.49.19-1.el8pc, 3.49.19-1.el9pc | 20.06.2024 |
SB20240620121 SB2024062832 SB2024070501 and 41 more |
||
| #VU92262 - Exposure of sensitive information to an unauthorized actor CVE-2024-37891 |
CWE-200 | Low | 3.28.32-1.el9ap, 3.49.19-1.el8pc, 3.49.19-1.el9pc | 19.06.2024 |
SB2024061955 SB20240625146 SB2024062605 and 194 more |
||
| #VU91160 - Improper input validation CVE-2024-24790 |
CWE-20 | Medium | 3.28.32-1.el9ap, 3.39.21-1.el8pc | 05.06.2024 |
SB2024060520 SB2024060635 SB2024060729 and 90 more |
||
| #VU89296 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-24788 |
CWE-835 | Medium | 3.28.32-1.el9ap | 09.05.2024 |
SB2024050936 SB2024050937 SB2024051029 and 43 more |
||
| #VU87734 - Resource exhaustion CVE-2024-28863 |
CWE-400 | Medium | 3.49.19-1.el8pc, 3.49.19-1.el9pc | 22.03.2024 |
SB2024032234 SB2024052306 SB2024061114 and 30 more |
Showing elements 1 - 20 out of 95