Known vulnerabilities in Red Hat Ceph Storage - page 7

Software CPE: cpe:2.3:a:red_hat:red_hat_ceph_storage:*:*:*:*:*:*:*:*
Total vulnerabilities: 205
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Red Hat Ceph Storage Red Hat Ceph Storage is affected by 205 known vulnerabilities: 27 high, 112 medium, 66 low Critical High Medium Low

Vulnerabilities (205)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81865 - Heap-based Buffer Overflow
CVE-2023-38545
CWE-122 High
Available
No
6.1 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 99 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
6.1 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU80801 - Exposure of sensitive information to an unauthorized actor
CVE-2023-4641
CWE-200 Low
No
No
6.1 14.09.2023 SB2023091453
SB2023091455
SB2023101019
and 66 more
#VU79586 - Access of Uninitialized Pointer
CVE-2023-36054
CWE-824 Medium
No
No
6.1 16.08.2023 SB2023081621
SB2023081623
SB2023081624
and 51 more
#VU78470 - Missing Authorization
CVE-2023-2183
CWE-862 Low
No
No
6.1 20.07.2023 SB20230720110
SB20230720114
SB20230720115
and 9 more
#VU77623 - Improper Synchronization
CVE-2023-2801
CWE-662 Medium
No
No
6.1 22.06.2023 SB2023062244
SB20230720114
SB20230720115
and 8 more
#VU77476 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4231
CWE-79 Low
No
No
6.1 16.06.2023 SB2022052637
SB2023061625
SB2023062315
and 3 more
#VU77351 - Improper input validation
CVE-2023-29499
CWE-20 Medium
No
No
6.1 15.06.2023 SB2023041955
SB2023061510
SB2023080276
and 35 more
#VU77350 - Resource exhaustion
CVE-2023-32611
CWE-400 Medium
No
No
6.1 15.06.2023 SB2023041955
SB2023061510
SB2023080276
and 31 more
#VU77349 - Resource exhaustion
CVE-2023-32665
CWE-400 Medium
No
No
6.1 15.06.2023 SB2023041955
SB2023061510
SB2023080276
and 31 more
#VU75360 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-1410
CWE-79 Low
No
No
6.1 19.04.2023 SB2023041950
SB2023041951
SB2023041952
and 11 more
#VU74299 - Missing release of memory after effective lifetime
CVE-2023-0836
CWE-401 Low
No
No
6.1 03.04.2023 SB2023033109
SB2023040342
SB2023041402
and 7 more
#VU72130 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31130
CWE-200 Medium
No
No
6.1 12.02.2023 SB2023021201
SB2023021202
SB2023021203
and 11 more
#VU72128 - Improper Verification of Cryptographic Signature
CVE-2022-31123
CWE-347 Medium
No
No
6.1 11.02.2023 SB2023021201
SB2023021202
SB2023021203
and 15 more
#VU68557 - Authentication Bypass Using an Alternate Path or Channel
CVE-2022-35957
CWE-288 Low
No
No
6.1 20.10.2022 SB2022092614
SB2022102094
SB2023050969
and 16 more
#VU67556 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-32190
CWE-22 Medium
No
No
6.1 21.09.2022 SB2022091520
SB2022092146
SB2022092946
and 33 more
#VU66121 - Improper input validation
CVE-2022-32189
CWE-20 Medium
No
No
6.1 04.08.2022 SB2022080502
SB2022080503
SB2022080511
and 81 more
#VU66066 - Security Features
CVE-2022-32148
CWE-254 Medium
No
No
6.1 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU65835 - Incorrect Regular Expression
CVE-2022-31129
CWE-185 Medium
No
No
6.1 27.07.2022 SB2022072729
SB2022072901
SB2022081048
and 102 more
#VU65353 - Improper Authentication
CVE-2022-31107
CWE-287 High
No
No
6.1 15.07.2022 SB2022071510
SB2022072642
SB2022072643
and 21 more


Showing elements 121 - 140 out of 205