It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cockpit-wsUpgrade cockpit-machines-ovirtUpgrade cockpit-debuginfoUpgrade cockpit-docUpgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-system | Apr 1, 2019 | Mar 19, 2019 |
| Debian | — | Upgrade cockpit | Jul 30, 2024 | Mar 26, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade cockpitUpgrade cockpit-storagedUpgrade cockpit-wsUpgrade cockpit-docUpgrade cockpit-bridgeUpgrade cockpit-systemUpgrade cockpit-packagekit | Feb 26, 2020 | Mar 26, 2019 |
| Oracle_linux | — | Upgrade cockpit-machines-ovirtUpgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-docUpgrade cockpit-wsUpgrade cockpit-system | Jul 21, 2020 | Dec 13, 2018 |
| Redhat_linux | — | Upgrade cockpitUpgrade cockpit-wsUpgrade cockpit-debuginfoUpgrade cockpit-bridgeUpgrade cockpit-systemUpgrade cockpit-docUpgrade cockpit-machines-ovirt | Mar 14, 2019 | Mar 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub