Known vulnerabilities in python3.11 (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python3.11 (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python3.11_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
12
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.11.7-1.el9_4.7
3.11.9-7.el9_5.2
3.11.11-1.el8_10
3.11.9-7.el9_5.1
3.11.9-7.el9
3.11.10-1.el8_10
3.11.7-1.el9_4.6
3.11.2-2.el8_8.4
3.11.2-2.el9_2.6
3.11.9-7.el8_10
3.11.2-2.el9_2.4
3.11.7-1.el9_4.1
3.11.9-1.el8_10
3.11.7-1.el8
3.11.7-1.el9
3.11.5-1.el8_9
3.11.5-1.el9_3
3.11.2-2.el9_2.2
3.11.2-2.el8_8.2
3.11.2-2.el8_8.1
3.11.2-2.el9_2.1
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-9287 |
CWE-78 | Low | 3.11.7-1.el9_4.7, 3.11.9-7.el9_5.2, 3.11.11-1.el8_10 | 28.10.2024 |
SB2024102836 SB2024102838 SB20241101111 and 117 more |
||
| #VU96745 - Incorrect Regular Expression CVE-2024-6232 |
CWE-185 | Medium | 3.11.2-2.el8_8.4, 3.11.2-2.el9_2.6, 3.11.7-1.el9_4.6, 3.11.9-7.el9_5.1, 3.11.10-1.el8_10 | 03.09.2024 |
SB2024090377 SB2024090927 SB2024091048 and 144 more |
||
| #VU96596 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-8088 |
CWE-835 | Medium | 3.11.9-7.el8_10, 3.11.9-7.el9 | 28.08.2024 |
SB2024082860 SB2024082861 SB2024082862 and 82 more |
||
| #VU95571 - Command injection CVE-2024-6923 |
CWE-77 | Medium | 3.11.2-2.el9_2.6, 3.11.9-7.el8_10 | 08.08.2024 |
SB2024080861 SB2024080862 SB2024080863 and 143 more |
||
| #VU95157 - Incorrect Provision of Specified Functionality CVE-2024-4032 |
CWE-684 | Medium | 3.11.9-7.el8_10 | 02.08.2024 |
SB2024080203 SB2024080207 SB2024080209 and 101 more |
||
| #VU87685 - Resource exhaustion CVE-2024-0450 |
CWE-400 | Medium | 3.11.9-1.el8_10, 3.11.9-7.el9 | 21.03.2024 |
SB2024032107 SB2024032110 SB2024040848 and 80 more |
||
| #VU87185 - UNIX Symbolic Link (Symlink) Following CVE-2023-6597 |
CWE-61 | Low | 3.11.2-2.el9_2.4, 3.11.7-1.el9_4.1, 3.11.9-1.el8_10 | 07.03.2024 |
SB2024030718 SB2024030726 SB2024030727 and 88 more |
||
| #VU82980 - Improper input validation CVE-2023-27043 |
CWE-20 | Medium | 3.11.7-1.el8, 3.11.7-1.el9 | 10.11.2023 |
SB2023041957 SB2023111064 SB2023111315 and 120 more |
||
| #VU80585 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-41105 |
CWE-22 | Low | 3.11.5-1.el8_9, 3.11.5-1.el9_3 | 11.09.2023 |
SB2023082825 SB2023100328 SB2023100362 and 18 more |
||
| #VU80228 - Cleartext Transmission of Sensitive Information CVE-2023-40217 |
CWE-319 | Medium | 3.11.2-2.el8_8.2, 3.11.2-2.el9_2.2 | 01.09.2023 |
SB2023090142 SB2023090143 SB2023090144 and 139 more |
||
| #VU72618 - Improper input validation CVE-2023-24329 |
CWE-20 | Medium | 3.11.2-2.el8_8.1, 3.11.2-2.el9_2.1 | 28.02.2023 |
SB2023022819 SB2023022822 SB2023030832 and 158 more |
||
| #VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2007-4559 |
CWE-22 | High | 3.11.5-1.el8_9, 3.11.5-1.el9_3 | 22.09.2022 |
SB2007082801 SB2022120206 SB2023060825 and 68 more |