Known vulnerabilities in Red Hat OpenShift Container Platform 3.11.104

Version: 3.11.104
Software CPE: cpe:2.3:a:red_hat:red_hat_openshift_container_platform:*:*:*:*:*:*:*:*
Total vulnerabilities: 75
Public exploits: 5
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Red Hat OpenShift Container Platform version 3.11.104 Red Hat OpenShift Container Platform 3.11.104 is affected by 75 vulnerabilities: 1 critical, 13 high, 41 medium, 20 low Critical High Medium Low

Vulnerabilities (75)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU66757 - Use After Free
CVE-2022-2526
CWE-416 Medium
No
No
3.11.784, 4.6.61, 4.7.59, 4.8.49, 4.9.48, 4.10.31, 4.11.3 25.08.2022 SB2022082509
SB2022082511
SB2022082531
and 48 more
#VU66189 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-29154
CWE-22 Low
No
No
3.11.784, 4.6.61, 4.7.59, 4.8.49, 4.9.48, 4.10.31, 4.11.3, 4.13.0 08.08.2022 SB2022080837
SB2022081645
SB2022081649
and 70 more
#VU65495 - Improper input validation
CVE-2022-34169
CWE-20 High
Public exploit available
No
3.11.784, 4.6.61, 4.7.56, 4.9.45, 4.10.25 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 137 more
#VU65496 - Improper input validation
CVE-2022-21541
CWE-20 Medium
No
No
3.11.784, 4.6.61, 4.7.56, 4.9.45, 4.10.25 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 105 more
#VU65497 - Improper input validation
CVE-2022-21540
CWE-20 Medium
No
No
3.11.784, 4.6.61, 4.7.56, 4.9.45, 4.10.25 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 105 more
#VU64484 - Reachable Assertion
CVE-2021-46784
CWE-617 Medium
No
No
3.11.784 18.06.2022 SB2022061801
SB2022062237
SB2022062908
and 20 more
#VU64364 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21123
CWE-200 Low
No
No
3.11.784, 4.8.53, 4.9.51, 4.10.39, 4.11.5 14.06.2022 SB2022061454
SB2022061465
SB2022061463
and 97 more
#VU64365 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21125
CWE-200 Low
No
No
3.11.784, 4.8.53, 4.9.51, 4.10.39, 4.11.5 14.06.2022 SB2022061454
SB2022061467
SB2022061463
and 96 more
#VU64366 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21166
CWE-200 Low
No
No
3.11.784, 4.8.53, 4.9.51, 4.10.39, 4.11.5 14.06.2022 SB2022061454
SB2022061466
SB2022061463
and 102 more
#VU64008 - Resource exhaustion
CVE-2022-1708
CWE-400 Medium
No
No
3.11.715, 4.6.59, 4.7.53, 4.8.43, 4.9.38, 4.10.18 07.06.2022 SB2022060707
SB2022061334
SB2022061627
and 15 more
#VU63885 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2022-1677
CWE-300 Medium
No
No
3.11.705, 4.6.58, 4.7.51, 4.8.41, 4.9.35, 4.10.13 31.05.2022 SB2022053117
SB2022053118
SB2022053119
and 3 more
#VU63126 - Permissions, Privileges, and Access Controls
CVE-2022-1552
CWE-264 Medium
No
No
3.11.784 12.05.2022 SB2022051213
SB2022051303
SB2022051304
and 48 more
#VU62399 - Improper input validation
CVE-2022-21426
CWE-20 Medium
No
No
3.11.705, 4.6.57, 4.7.50, 4.8.41 19.04.2022 SB2022041944
SB2022041945
SB2022042102
and 129 more
#VU62401 - Improper input validation
CVE-2022-21434
CWE-20 Medium
No
No
3.11.705, 4.6.57, 4.7.50, 4.8.41 19.04.2022 SB2022041944
SB2022041945
SB2022042102
and 111 more
#VU62002 - Improper input validation
CVE-2022-1271
CWE-20 High
No
No
3.11.705, 3.11.784, 4.6.58, 4.7.51, 4.8.41, 4.9.35, 4.11.0, 4.11.45, 4.13.0 08.04.2022 SB2022040803
SB2022040804
SB2022040822
and 134 more
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
3.11.705, 4.6.58, 4.7.51, 4.8.41, 4.9.35, 4.11.0 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU57320 - Improper Access Control
CVE-2021-39226
CWE-284 Medium
Public exploit available
Exploited
3.11.784, 4.6.61, 4.7.59, 4.8.49, 4.9.48 12.10.2021 SB2021101262
SB2021101320
SB2021101321
and 22 more
#VU49973 - Memory corruption
CVE-2021-3177
CWE-119 High
No
No
3.11.784 19.01.2021 SB2021012516
SB2021012517
SB2021022418
and 54 more
#VU47403 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26137
CWE-93 Medium
No
No
3.11.374, 3.11.784 30.09.2020 SB2020100716
SB2020121420
SB2021052028
and 35 more
#VU48592 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26116
CWE-93 Medium
No
No
3.11.784 27.09.2020 SB2020092711
SB2020112308
SB2020112309
and 34 more


Showing elements 1 - 20 out of 75