Known vulnerabilities in Red Hat OpenStack - page 3

Software CPE: cpe:2.3:a:red_hat:red_hat_openstack:*:*:*:*:*:*:*:*
Total vulnerabilities: 406
Public exploits: 29
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Red Hat OpenStack Red Hat OpenStack is affected by 406 known vulnerabilities: 1 critical, 59 high, 203 medium, 143 low Critical High Medium Low

Vulnerabilities (406)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100770 - Information Exposure Through Log Files
CVE-2024-4840
CWE-532 Low
No
No
17.1.4 21.11.2024 SB2024112112
#VU96470 - Exposure of sensitive information to an unauthorized actor
CVE-2024-40767
CWE-200 Low
No
No
16.1.9, 17.1.3 23.08.2024 SB2024082303
SB2024082309
SB2024082310
and 2 more
#VU96055 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-42353
CWE-601 Low
No
No
17.1.4, 18.0 15.08.2024 SB2024081552
SB2024081555
SB2024081556
and 44 more
#VU94188 - Improper input validation
CVE-2024-39614
CWE-20 Medium
Available
No
18.0.3 12.07.2024 SB2024071225
SB2024071228
SB2024071229
and 15 more
#VU94184 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-39330
CWE-22 Medium
No
No
18.0.3 12.07.2024 SB2024071225
SB2024071228
SB2024071229
and 13 more
#VU94183 - Exposure of sensitive information to an unauthorized actor
CVE-2024-39329
CWE-200 Medium
No
No
18.0.3 12.07.2024 SB2024071225
SB2024071228
SB2024071229
and 14 more
#VU94182 - Improper input validation
CVE-2024-38875
CWE-20 Medium
No
No
18.0.3 12.07.2024 SB2024071225
SB2024071228
SB2024071229
and 13 more
#VU93874 - Dependency on Vulnerable Third-Party Component
CVE-2024-4438
CWE-1395 Medium
No
No
17.1 09.07.2024 SB2024070925
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
17.1.4 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 194 more
#VU89381 - Uncontrolled Recursion
CVE-2024-4340
CWE-674 Medium
No
No
17.1.4 13.05.2024 SB2024051329
SB2024051330
SB2024051352
and 15 more
#VU89167 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-1135
CWE-444 Medium
No
No
16.2 06.05.2024 SB2024050631
SB2024050632
SB2024050633
and 40 more
#VU89149 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-34069
CWE-94 Medium
No
No
16.2, 17.1.4 06.05.2024 SB2024050606
SB2024050723
SB2024050930
and 54 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
16.2, 17.1 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU87916 - Exposure of sensitive information to an unauthorized actor
CVE-2024-29156
CWE-200 Medium
No
No
16.2 29.03.2024 SB2024032948
SB2024032949
SB2024032950
and 6 more
#VU87830 - Missing release of memory after effective lifetime
CVE-2024-1394
CWE-401 Medium
No
No
17.1 26.03.2024 SB2024032646
SB2024032647
SB2024032648
and 54 more
#VU86309 - Observable discrepancy
CVE-2023-45287
CWE-203 Medium
No
No
17.1 09.02.2024 SB2024020943
SB2024020944
SB2024021315
and 37 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
16.2, 17.1 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU83928 - Resource exhaustion
CVE-2023-39326
CWE-400 Medium
No
No
16.2, 17.1 06.12.2023 SB2023120641
SB2023121133
SB2023121156
and 90 more
#VU80421 - Out-of-bounds read
CVE-2022-48554
CWE-125 Low
No
No
17.1 05.09.2023 SB2023090535
SB2023090536
SB2023091257
and 52 more
#VU78265 - Improper Authentication
CVE-2023-2975
CWE-287 Low
No
No
17.1 15.07.2023 SB2023071506
SB2023072844
SB2023072846
and 37 more


Showing elements 41 - 60 out of 406