It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-debuginfoUpgrade cockpit-docUpgrade cockpit-machines-ovirtUpgrade cockpit-wsUpgrade cockpit-system | Apr 1, 2019 | Mar 19, 2019 |
| Debian | — | Upgrade cockpit | Jul 30, 2024 | Mar 26, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade cockpit-docUpgrade cockpit-bridgeUpgrade cockpit-packagekitUpgrade cockpit-systemUpgrade cockpitUpgrade cockpit-wsUpgrade cockpit-storaged | Feb 26, 2020 | Mar 26, 2019 |
| Oracle_linux | — | Upgrade cockpit-docUpgrade cockpit-wsUpgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpit-machines-ovirtUpgrade cockpit | Jul 21, 2020 | Dec 13, 2018 |
| Redhat_linux | — | Upgrade cockpit-wsUpgrade cockpit-machines-ovirtUpgrade cockpit-bridgeUpgrade cockpit-docUpgrade cockpit-debuginfoUpgrade cockpit-systemUpgrade cockpit | Mar 14, 2019 | Mar 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub