redpanda records
3 published records for vendor redpanda.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-522 Insufficiently Protected Credentials1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-50976No exploit | Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.redpanda · redpanda · CWE-862 | Critical9.8 | — | 1.0% | Dec 17, 2023 |
22Monitor | CVE-2023-24619No exploit | Redpanda before 22.3.12 discloses cleartext AWS credentials.redpanda · redpanda · CWE-522 | Medium5.5 | — | 0.3% | Feb 13, 2023 |
17Monitor | CVE-2023-30450No exploit | rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data typredpanda · redpanda · CWE-20 | Medium4.3 | — | 0.6% | Apr 8, 2023 |
- CVE-2023-5097639Monitor
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
CriticalCVSS 9.8No exploitEPSS 1%redpanda · redpandaDec 17, 2023
- CVE-2023-2461922Monitor
Redpanda before 22.3.12 discloses cleartext AWS credentials.
MediumCVSS 5.5No exploitEPSS 0%redpanda · redpandaFeb 13, 2023
- CVE-2023-3045017Monitor
rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data typ
MediumCVSS 4.3No exploitEPSS 1%redpanda · redpandaApr 8, 2023