A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-systemUpgrade cockpit-packagekitUpgrade cockpit-pcpUpgrade cockpit-docUpgrade cockpit-wsUpgrade cockpit-storaged | Jun 7, 2024 | Mar 28, 2024 |
| Debian | — | Upgrade cockpit | Apr 8, 2024 | Mar 28, 2024 |
| Oracle_linux | — | Upgrade cockpit-storagedUpgrade cockpit-wsUpgrade cockpit-docUpgrade cockpit-pcpUpgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpit-packagekitUpgrade cockpit | Jun 6, 2024 | Mar 27, 2024 |
| Redhat_linux | — | Upgrade cockpit-debuginfoUpgrade cockpit-storagedUpgrade cockpit-packagekitUpgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-wsUpgrade cockpit-pcpUpgrade cockpit-systemUpgrade cockpit-docUpgrade cockpit-debugsource | Jun 7, 2024 | Mar 28, 2024 |
| Rocky_linux | — | Upgrade cockpit-debugsourceUpgrade cockpit-debuginfoUpgrade cockpit-wsUpgrade cockpit-bridgeUpgrade cockpit | Jun 17, 2024 | Mar 28, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub