It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cockpit-bridgeUpgrade cockpit-machines-ovirtUpgrade cockpit-wsUpgrade cockpit-docUpgrade cockpit-debuginfoUpgrade cockpitUpgrade cockpit-system | Apr 1, 2019 | Mar 19, 2019 |
| Debian | — | Upgrade cockpit | Jul 30, 2024 | Mar 26, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpit-docUpgrade cockpit-packagekitUpgrade cockpit-wsUpgrade cockpitUpgrade cockpit-storaged | Feb 26, 2020 | Mar 26, 2019 |
| Oracle_linux | — | Upgrade cockpit-docUpgrade cockpit-systemUpgrade cockpit-wsUpgrade cockpit-bridgeUpgrade cockpit-machines-ovirtUpgrade cockpit | Jul 21, 2020 | Dec 13, 2018 |
| Redhat_linux | — | Upgrade cockpitUpgrade cockpit-machines-ovirtUpgrade cockpit-debuginfoUpgrade cockpit-systemUpgrade cockpit-wsUpgrade cockpit-docUpgrade cockpit-bridge | Mar 14, 2019 | Mar 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub