CVE-2024-6126
- EPSS 0.02%
- Veröffentlicht 03.07.2024 15:15:06
- Zuletzt bearbeitet 21.11.2024 09:49:01
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
- EPSS 0.04%
- Veröffentlicht 04.04.2024 14:15:09
- Zuletzt bearbeitet 12.12.2024 22:15:07
A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, therefore, running the resulting application inherits the values captured at build time. ...
CVE-2024-2947
- EPSS 0.03%
- Veröffentlicht 28.03.2024 19:15:48
- Zuletzt bearbeitet 21.11.2024 09:10:54
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
CVE-2021-3698
- EPSS 0.15%
- Veröffentlicht 10.03.2022 17:42:57
- Zuletzt bearbeitet 21.11.2024 06:22:10
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Cert...
CVE-2021-3660
- EPSS 0.27%
- Veröffentlicht 10.03.2022 17:42:55
- Zuletzt bearbeitet 21.11.2024 06:22:05
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar...
CVE-2020-35850
- EPSS 0.45%
- Veröffentlicht 30.12.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:28:18
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
CVE-2019-3804
- EPSS 4.55%
- Veröffentlicht 26.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:34
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which c...