Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade cockpitUpgrade cockpit-docUpgrade cockpit-bridgeUpgrade cockpit-wsUpgrade cockpit-system | May 13, 2022 | Mar 10, 2022 |
| Centos_linux | — | Upgrade cockpitUpgrade cockpit-debuginfoUpgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpit-debugsourceUpgrade cockpit-wsUpgrade cockpit-doc | May 13, 2022 | Mar 10, 2022 |
| Debian | — | Upgrade cockpit | Jul 30, 2024 | Mar 10, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade cockpit-wsUpgrade cockpit-docUpgrade cockpitUpgrade cockpit-bridgeUpgrade cockpit-packagekitUpgrade cockpit-storagedUpgrade cockpit-system | Dec 28, 2021 | Dec 25, 2021 |
| Oracle_linux | — | Upgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-docUpgrade cockpit-ws | May 18, 2022 | Jul 20, 2021 |
| Redhat_linux | — | Upgrade cockpit-debuginfoUpgrade cockpit-docUpgrade cockpitNo solution existsUpgrade cockpit-debugsourceUpgrade cockpit-bridgeUpgrade cockpit-systemUpgrade cockpit-ws | May 13, 2022 | Mar 10, 2022 |
| Rocky_linux | — | Upgrade cockpit-wsUpgrade cockpitUpgrade cockpit-bridgeUpgrade cockpit-debuginfoUpgrade cockpit-debugsource | Mar 5, 2024 | Mar 10, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 10, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub