Known vulnerabilities in vdsm (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:vdsm_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 16
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting vdsm (Red Hat package) vdsm (Red Hat package) is affected by 16 known vulnerabilities: 1 high, 6 medium, 9 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75562 - Improper input validation
CVE-2023-20861
CWE-20 Medium
No
No
4.50.3.8-1.el8ev 27.04.2023 SB2023042742
SB2023042746
SB2023042832
and 61 more
#VU75561 - Improper input validation
CVE-2023-20860
CWE-20 Medium
No
No
4.50.3.8-1.el8ev 27.04.2023 SB2023042742
SB2023042746
SB2023050518
and 34 more
#VU70530 - Deserialization of Untrusted Data
CVE-2022-45047
CWE-502 High
Available
No
4.50.3.6-1.el8ev 28.12.2022 SB2022122828
SB2022122920
SB2023011148
and 49 more
#VU65835 - Incorrect Regular Expression
CVE-2022-31129
CWE-185 Medium
No
No
4.50.2.2-1.el8ev 27.07.2022 SB2022072729
SB2022072901
SB2022081048
and 102 more
#VU55601 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-30483
CWE-22 Medium
No
No
4.50.3.6-1.el8ev 05.08.2021 SB2021080512
SB2023011148
#VU54394 - Incorrect Regular Expression
CVE-2020-28500
CWE-185 Medium
No
No
4.40.80.5-1.el8ev 27.06.2021 SB2021062702
SB2021062703
SB2021090905
and 30 more
#VU53202 - Command injection
CVE-2021-23337
CWE-77 Medium
No
No
4.40.80.5-1.el8ev 12.05.2021 SB2021021525
SB2021051230
SB2021062703
and 59 more
#VU50040 - Heap-based Buffer Overflow
CVE-2021-3156
CWE-122 Low
Available
Exploited
4.30.51-1.el7ev 26.01.2021 SB2021012632
SB2021012633
SB2021012634
and 55 more
#VU49845 - Insufficient Verification of Data Authenticity
CVE-2020-25686
CWE-345 Low
Available
No
4.30.51-1.el7ev 20.01.2021 SB2021012070
SB20210120108
SB20210120122
and 27 more
#VU49844 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-25685
CWE-327 Low
Available
No
4.30.51-1.el7ev 20.01.2021 SB2021012070
SB20210120107
SB20210120122
and 27 more
#VU49843 - Insufficient Verification of Data Authenticity
CVE-2020-25684
CWE-345 Low
Available
No
4.30.51-1.el7ev 20.01.2021 SB2021012070
SB20210120106
SB20210120122
and 27 more
#VU28395 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12127
CWE-200 Low
No
No
4.20.49-1.el7ev, 4.30.13-4.el7ev 30.05.2019 SB2019053010
SB2019051422
SB2019072469
and 67 more
#VU28396 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12130
CWE-200 Low
No
No
4.20.49-1.el7ev, 4.30.13-4.el7ev 30.05.2019 SB2019053011
SB2019051422
SB2019072469
and 67 more
#VU28397 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12126
CWE-200 Low
No
No
4.20.49-1.el7ev, 4.30.13-4.el7ev 30.05.2019 SB2019053012
SB2019051422
SB2019072469
and 67 more
#VU28398 - Exposure of sensitive information to an unauthorized actor
CVE-2019-11091
CWE-200 Low
No
No
4.20.49-1.el7ev, 4.30.13-4.el7ev 30.05.2019 SB2019053013
SB2019051422
SB2019072469
and 67 more
#VU17772 - Command injection
CVE-2019-3831
CWE-77 Low
No
No
4.30.18-1.0.el7rhgs 19.02.2019 SB2019021915
SB2019030503
SB2019030504
and 1 more