Known vulnerabilities in Red Hat Ceph Storage - page 6

Software CPE: cpe:2.3:a:red_hat:red_hat_ceph_storage:*:*:*:*:*:*:*:*
Total vulnerabilities: 205
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Red Hat Ceph Storage Red Hat Ceph Storage is affected by 205 known vulnerabilities: 27 high, 112 medium, 66 low Critical High Medium Low

Vulnerabilities (205)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU92186 - Permissions, Privileges, and Access Controls
CVE-2023-4822
CWE-264 Low
No
No
7.1 17.06.2024 SB2023101664
SB2024061802
SB2024071933
#VU85833 - Resource exhaustion
CVE-2023-46159
CWE-400 Low
No
No
8.1 26.01.2024 SB2024012623
SB2024020929
SB2024110890
and 4 more
#VU85583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-49569
CWE-22 Medium
No
No
5.3, 7.1 18.01.2024 SB2024011878
SB2024011879
SB2024020832
and 42 more
#VU85582 - Resource exhaustion
CVE-2023-49568
CWE-400 Medium
No
No
7.1 18.01.2024 SB2024011878
SB2024011879
SB2024020832
and 37 more
#VU83546 - Resource exhaustion
CVE-2023-45142
CWE-400 Medium
No
No
5.3 29.11.2023 SB2023112912
SB2023112913
SB2023112949
and 54 more
#VU82112 - Improper Authorization
CVE-2023-43040
CWE-285 Medium
Available
No
- 17.10.2023 SB2023101761
SB2023112450
SB2024012922
and 5 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
5.3, 6.1, 7.1 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
5.3, 6.1, 7.1 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU79344 - Double Free
CVE-2023-39975
CWE-415 Medium
No
No
6.1 10.08.2023 SB2023081014
SB20230821173
SB2023110766
and 26 more
#VU77652 - Improper Authentication
CVE-2023-3128
CWE-287 High
No
No
7.1 22.06.2023 SB2023062281
SB2023071336
SB20230720114
and 15 more
#VU77620 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1387
CWE-200 Medium
No
No
6.1 22.06.2023 SB2023062227
SB2023062230
SB2023062231
and 7 more
#VU75359 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-0594
CWE-79 Low
No
No
- 19.04.2023 SB2023041949
SB2023041951
SB2023041952
and 6 more
#VU75358 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-0507
CWE-79 Low
No
No
- 19.04.2023 SB2023041949
SB2023041951
SB2023041952
and 6 more
#VU75141 - Memory corruption
CVE-2023-29491
CWE-119 Low
No
No
6.1 14.04.2023 SB2023041454
SB2023052328
SB2023052346
and 132 more
#VU74574 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24538
CWE-94 High
No
No
- 06.04.2023 SB2023040668
SB2023040678
SB2023040679
and 85 more
#VU72675 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-22462
CWE-79 Low
No
No
- 01.03.2023 SB2023030114
SB2023110239
SB2024020931
and 1 more
#VU72334 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-25725
CWE-444 Medium
No
No
- 16.02.2023 SB2023021659
SB2023021662
SB2023021663
and 22 more
#VU71740 - Exposure of sensitive information to an unauthorized actor
CVE-2022-23498
CWE-200 Medium
No
No
- 01.02.2023 SB2023020152
SB2023121104
SB2024020931
and 1 more
#VU71431 - Improper input validation
CVE-2023-0056
CWE-20 Medium
No
No
- 23.01.2023 SB2023012331
SB2023012332
SB2023012641
and 20 more
#VU70334 - Allocation of Resources Without Limits or Throttling
CVE-2022-41717
CWE-770 Medium
Available
No
- 14.12.2022 SB2022121432
SB2022121433
SB2022121435
and 185 more


Showing elements 101 - 120 out of 205