Known vulnerabilities in Red Hat OpenStack 12

Version: 12
Software CPE: cpe:2.3:a:red_hat:red_hat_openstack:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Red Hat OpenStack version 12 Red Hat OpenStack 12 is affected by 15 vulnerabilities: 2 medium, 13 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU16341 - Improper input validation
CVE-2018-14635
CWE-20 Low
No
No
- 07.12.2018 SB2018061413
SB2018120513
SB2018091706
and 1 more
#VU14477 - Improper input validation
CVE-2018-14432
CWE-20 Low
No
No
- 17.08.2018 SB2018082105
SB2018082106
SB2018082210
and 2 more
#VU13375 - Heap-based Buffer Overflow
CVE-2018-11806
CWE-122 Low
No
No
- 16.06.2018 SB2018061802
SB2018080616
SB2018081714
and 9 more
#VU12911 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2018-3639
CWE-362 Low
No
No
- 22.05.2018 SB2018052201
SB2018052207
SB2018052208
and 142 more
#VU12658 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1059
CWE-200 Low
No
No
- 14.05.2018 SB2018021104
SB2018043010
SB2018060604
and 7 more
#VU11845 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2017-1000385
CWE-300 Low
Public exploit available
Exploited
- 16.04.2018 SB2017120816
SB2018041212
SB2018031524
and 6 more
#VU11818 - Improper input validation
CVE-2017-13673
CWE-20 Low
No
No
- 11.04.2018 SB2018041304
SB2019032903
SB2018041048
and 5 more
#VU11819 - Use After Free
CVE-2017-13711
CWE-416 Low
No
No
- 11.04.2018 SB2018041304
SB2018060814
SB2018041048
and 1 more
#VU11644 - Out-of-bounds read
CVE-2017-13672
CWE-125 Low
No
No
- 10.04.2018 SB2018041005
SB2017120814
SB2017120815
and 12 more
#VU11464 - Permissions, Privileges, and Access Controls
CVE-2017-12155
CWE-264 Low
No
No
- 28.03.2018 SB2017091908
#VU11232 - Uncontrolled Memory Allocation
CVE-2017-15124
CWE-789 Medium
No
No
- 23.03.2018 SB2018032301
SB2018032302
SB2018032704
and 7 more
#VU11231 - Resource exhaustion
CVE-2017-15119
CWE-400 Medium
No
No
- 23.03.2018 SB2018032301
SB2018032302
SB2018032704
and 4 more
#VU11194 - Insufficient Control of Network Message Volume (Network Amplification)
CVE-2018-1000115
CWE-406 Low
Public exploit available
No
- 21.03.2018 SB2018030509
SB2018060712
SB2018082314
and 5 more
#VU10961 - Insufficiently Protected Credentials
CVE-2018-1000060
CWE-522 Low
No
No
- 13.03.2018 SB2018012001
SB2018032822
SB2018041203
and 1 more
#VU10565 - Double Free
CVE-2017-16820
CWE-415 Low
No
No
- 14.02.2018 SB2018010420
SB2018021414
SB2018032103
and 9 more