Known vulnerabilities in Red Hat OpenShift GitOps - page 6
Vendor:
Red Hat Inc.
Software:
Red Hat OpenShift GitOps
Software CPE:
cpe:2.3:a:red_hat:red_hat_openshift_gitops:*:*:*:*:*:*:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
241
Public exploits:
21
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
1.20.6
1.19.6
1.19.5
1.21.1
1.20.5
1.20.4
1.19.4
1.18.6
1.20.2
1.19.3
1.18.5
1.19.2
1.18.4
1.17.5
1.19.1
1.17.4
1.18.3
1.17.2
1.17.1
1.17.0
1.18.1
1.18.0
1.16.4
1.16.3
1.16.2
1.16.0
1.17.3
1.18.2
1.16.5
1.16.1
1.15.3
1.14.4
1.15.2
1.12.6
1.13.2
1.12.5
1.11.7
1.13.1
1.11.6
1.12.4
1.10.5
1.12.2
1.11.4
1.10.6
1.12.3
1.11.5
1.12.1
1.10.4
1.10.3
1.10.2
1.11.3
1.11.2
1.11.1
1.12.0
1.11
1.9.3
1.9.2
1.9.1
1.10.1
1.10.0
1.9
1.8
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.7
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5
1.4.4
1.4.3
1.4.2
1.4.1
1.2.3
1.2.2
1.2.1
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.4
1.3
1.2
1.1
1.0
Vulnerabilities (241)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU129013 - Use of a Broken or Risky Cryptographic Algorithm CVE-2024-31989 |
CWE-327 | Medium | 1.10.6, 1.11.5, 1.12.3 | 21.05.2024 |
SB2024052149 SB20240611291 SB20240611292 and 1 more |
||
| #VU89009 - Resource exhaustion CVE-2024-29893 |
CWE-400 | Medium | 1.10.4, 1.11.3, 1.12.1 | 25.04.2024 |
SB2024042557 SB2024042564 SB2024042565 and 2 more |
||
| #VU89008 - Security Features CVE-2024-21662 |
CWE-254 | Medium | 1.10.4, 1.11.3, 1.12.1 | 25.04.2024 |
SB2024042556 SB2024042564 SB2024042565 and 2 more |
||
| #VU89007 - Security Features CVE-2024-21652 |
CWE-254 | Medium | 1.10.4, 1.11.3, 1.12.1 | 25.04.2024 |
SB2024042556 SB2024042564 SB2024042565 and 2 more |
||
| #VU89006 - Resource Management Errors CVE-2024-21661 |
CWE-399 | Medium | 1.10.4, 1.11.3, 1.12.1 | 25.04.2024 |
SB2024042556 SB2024042564 SB2024042565 and 2 more |
||
| #VU129003 - Improper Access Control CVE-2024-31990 |
CWE-284 | Low | 1.12.2 | 15.04.2024 |
SB2024041578 SB20240611289 |
||
| #VU88226 - Missing release of memory after effective lifetime CVE-2024-26461 |
CWE-401 | Medium | 1.10.6, 1.11.5, 1.12.3 | 09.04.2024 |
SB2024040939 SB2024040943 SB20240611102 and 46 more |
||
| #VU88225 - Missing release of memory after effective lifetime CVE-2024-26458 |
CWE-401 | Medium | 1.10.6, 1.11.5, 1.12.3 | 09.04.2024 |
SB2024040938 SB2024040943 SB20240611102 and 47 more |
||
| #VU87525 - Improper Access Control CVE-2023-50726 |
CWE-284 | Medium | 1.10.4, 1.11.3, 1.12.1 | 14.03.2024 |
SB2024031428 SB2024042564 SB2024042565 and 2 more |
||
| #VU87524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-28175 |
CWE-79 | Low | 1.10.0, 1.11, 1.12.0 | 14.03.2024 |
SB2024031428 SB2024031970 SB2024031971 and 1 more |
||
| #VU86885 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-48624 |
CWE-78 | Medium | 1.10.4, 1.11.3, 1.11.6, 1.12.1, 1.12.5, 1.13.1 | 28.02.2024 |
SB2024022820 SB2024022839 SB2024030503 and 60 more |
||
| #VU86230 - Resource exhaustion CVE-2023-52425 |
CWE-400 | Medium | 1.10.4, 1.10.6, 1.11.3, 1.12.1, 1.12.4 | 07.02.2024 |
SB2024020750 SB2024020754 SB2024020765 and 120 more |
||
| #VU85658 - Insufficient Verification of Data Authenticity CVE-2023-7008 |
CWE-345 | Medium | 1.10.6, 1.11.5, 1.12.3 | 22.01.2024 |
SB2024012238 SB2024012239 SB2024012240 and 38 more |
||
| #VU85552 - Resource exhaustion CVE-2024-22365 |
CWE-400 | Low | 1.10.6, 1.11.5, 1.12.3 | 17.01.2024 |
SB2024011799 SB20240117126 SB2024011839 and 44 more |
||
| #VU84985 - Out-of-bounds read CVE-2023-7104 |
CWE-125 | Medium | 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.0, 1.12.5, 1.13.1 | 04.01.2024 |
SB2024010417 SB2024010420 SB2024010516 and 108 more |
||
| #VU83900 - Exposure of sensitive information to an unauthorized actor CVE-2023-46218 |
CWE-200 | Low | 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.1 | 06.12.2023 |
SB2023120612 SB2023120644 SB2023120661 and 87 more |
||
| #VU81863 - External Control of File Name or Path CVE-2023-38546 |
CWE-73 | Low | 1.9.3, 1.10.4, 1.11.3, 1.12.1 | 11.10.2023 |
SB2023101129 SB2023101135 SB2023101149 and 125 more |
||
| #VU76238 - Expected Behavior Violation CVE-2023-28322 |
CWE-440 | Medium | 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.1 | 17.05.2023 |
SB2023051752 SB2023051760 SB2023051761 and 88 more |
||
| #VU74146 - Improper Privilege Management CVE-2023-26604 |
CWE-269 | Low | 1.10.4, 1.11.3, 1.12.0 | 28.03.2023 |
SB2023032869 SB2023032871 SB2023040540 and 56 more |
||
| #VU63553 - Integer overflow CVE-2021-43618 |
CWE-190 | Medium | 1.10.4, 1.11.3, 1.12.0, 1.12.1 | 24.05.2022 |
SB2021121654 SB2022052401 SB2021120223 and 85 more |
Showing elements 101 - 120 out of 241