Known vulnerabilities in python-requests (Red Hat package) - page 4

Software CPE: cpe:2.3:o:red_hat:python-requests_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 75
Public exploits: 6
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting python-requests (Red Hat package) python-requests (Red Hat package) is affected by 75 known vulnerabilities: 10 high, 50 medium, 15 low Critical High Medium Low

Vulnerabilities (75)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU79815 - Exposure of sensitive information to an unauthorized actor
CVE-2023-4380
CWE-200 Low
No
No
2.31.0-1.el9ap 22.08.2023 SB2023082206
#VU77880 - Inefficient Regular Expression Complexity
CVE-2023-36053
CWE-1333 Medium
No
No
2.31.0-1.el9ap 03.07.2023 SB2023070325
SB2023070532
SB2023071502
and 16 more
#VU77164 - Exposure of sensitive information to an unauthorized actor
CVE-2023-32681
CWE-200 Medium
Available
No
2.20.0-3.el8_6, 2.20.0-3.el8_8, 2.25.1-7.el9_2, 2.31.0-1.el9ap 12.06.2023 SB2023061224
SB2023061306
SB2023061514
and 114 more
#VU72036 - Error Handling
CVE-2023-23931
CWE-388 Low
No
No
2.31.0-1.el9ap 08.02.2023 SB2023020813
SB2023030952
SB2023031419
and 68 more
#VU62051 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28347
CWE-89 High
No
No
2.27.1-2.el8ui 11.04.2022 SB2022041110
SB2022041125
SB2022041267
and 8 more
#VU62050 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28346
CWE-89 High
Available
No
2.27.1-2.el8ui 11.04.2022 SB2022041110
SB2022041125
SB2022041126
and 14 more
#VU54626 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3583
CWE-94 High
No
No
2.25.1-1.el8pc 08.07.2021 SB2021070822
SB2021070823
SB2021071517
and 12 more
#VU54077 - Resource exhaustion
CVE-2021-33503
CWE-400 Medium
No
No
2.25.1-1.el7pc 13.06.2021 SB2021061304
SB2021061305
SB2021071501
and 36 more
#VU52502 - Improper input validation
CVE-2020-27218
CWE-20 Medium
No
No
2.19.1-5.el7 23.04.2021 SB2021042305
SB2021042635
SB2021063002
and 15 more
#VU52495 - Permissions, Privileges, and Access Controls
CVE-2021-21645
CWE-264 Low
No
No
2.19.1-5.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52494 - Cross-Site Request Forgery (CSRF)
CVE-2021-21644
CWE-352 Low
No
No
2.19.1-5.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52493 - Permissions, Privileges, and Access Controls
CVE-2021-21643
CWE-264 Low
No
No
2.19.1-5.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52492 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-21642
CWE-611 Medium
No
No
2.19.1-5.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52385 - Improper input validation
CVE-2020-27223
CWE-20 Medium
Available
No
2.19.1-5.el7 21.04.2021 SB2021042107
SB2021063002
SB2021063034
and 19 more
#VU48942 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-27216
CWE-362 Low
No
No
2.19.1-5.el7 23.10.2020 SB2020121307
SB2020121308
SB2021012011
and 27 more


Showing elements 61 - 80 out of 75