Known vulnerabilities in Red Hat Software Collections 1 for RHEL 7 - page 4

Version: 1 for RHEL 7
Software CPE: cpe:2.3:a:red_hat:red_hat_software_collections:*:*:*:*:*:*:*:*
Total vulnerabilities: 340
Public exploits: 10
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Red Hat Software Collections version 1 for RHEL 7 Red Hat Software Collections 1 for RHEL 7 is affected by 340 vulnerabilities: 34 high, 209 medium, 97 low Critical High Medium Low

Vulnerabilities (340)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
- 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 53 more
#VU62608 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-29599
CWE-78 High
No
No
- 26.04.2022 SB2022042627
SB2022042724
SB2022050234
and 29 more
#VU61681 - Server-Side Request Forgery (SSRF)
CVE-2021-4189
CWE-918 Medium
No
No
- 29.03.2022 SB2022032904
SB2022032905
SB2022032907
and 42 more
#VU61675 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-0391
CWE-93 Medium
No
No
- 29.03.2022 SB2022032903
SB2022032905
SB2022032907
and 49 more
#VU61286 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-22720
CWE-444 Medium
No
No
- 14.03.2022 SB2022031416
SB2022031504
SB2022031724
and 56 more
#VU60291 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-23959
CWE-444 Medium
No
No
- 03.02.2022 SB2022020331
SB2022020415
SB2022020416
and 14 more
#VU59660 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-43818
CWE-79 Low
No
No
- 17.01.2022 SB2022011721
SB2022011724
SB2022050418
and 23 more
#VU59551 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21824
CWE-94 Medium
No
No
- 12.01.2022 SB2022011216
SB2022041205
SB2022060315
and 39 more
#VU59550 - Improper Certificate Validation
CVE-2021-44533
CWE-295 Medium
No
No
- 12.01.2022 SB2022011216
SB2022041522
SB2022042517
and 36 more
#VU59549 - Improper Validation of Certificate with Host Mismatch
CVE-2021-44532
CWE-297 Medium
No
No
- 12.01.2022 SB2022011216
SB2022041522
SB2022042806
and 36 more
#VU59548 - Improper Certificate Validation
CVE-2021-44531
CWE-295 Medium
No
No
- 12.01.2022 SB2022011216
SB2022032010
SB2022041522
and 35 more
#VU59089 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-3737
CWE-835 Low
No
No
- 22.12.2021 SB2021122214
SB2022050235
SB2022051138
and 58 more
#VU58295 - Resource Management Errors
CVE-2021-3733
CWE-399 Low
No
No
- 23.11.2021 SB2021112309
SB2021122214
SB2022050235
and 41 more
#VU58203 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37712
CWE-22 Medium
No
No
- 17.11.2021 SB2021111707
SB2021111710
SB2022031104
and 24 more
#VU58202 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37701
CWE-22 Medium
No
No
- 17.11.2021 SB2021111706
SB2021111710
SB2022031104
and 24 more
#VU55666 - Insufficient Verification of Data Authenticity
CVE-2020-36327
CWE-345 High
No
No
- 09.08.2021 SB2021080910
SB2021080913
SB2021092218
and 21 more
#VU55489 - Improper Certificate Validation
CVE-2021-32066
CWE-295 Medium
No
No
- 02.08.2021 SB2021080209
SB2021080210
SB2021080913
and 28 more
#VU55488 - Exposure of sensitive information to an unauthorized actor
CVE-2021-31810
CWE-200 Medium
No
No
- 02.08.2021 SB2021080209
SB2021080210
SB2021080913
and 27 more
#VU52796 - Command injection
CVE-2021-31799
CWE-77 High
No
No
- 03.05.2021 SB2021050306
SB2021052413
SB2021052414
and 27 more
#VU47481 - Improper input validation
CVE-2020-13956
CWE-20 Medium
No
No
- 09.10.2020 SB2020100902
SB2020101604
SB2021042104
and 77 more


Showing elements 61 - 80 out of 340