A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade cockpitUpgrade cockpit-bridgeUpgrade cockpit-docUpgrade cockpit-wsUpgrade cockpit-system | May 13, 2022 | Mar 10, 2022 |
| Centos_linux | — | Upgrade cockpit-docUpgrade cockpit-debuginfoUpgrade cockpitUpgrade cockpit-bridgeUpgrade cockpit-wsUpgrade cockpit-debugsourceUpgrade cockpit-system | May 13, 2022 | Mar 10, 2022 |
| Debian | — | Upgrade cockpit | Jul 30, 2024 | Mar 10, 2022 |
| Oracle_linux | — | Upgrade cockpitUpgrade cockpit-systemUpgrade cockpit-bridgeUpgrade cockpit-wsUpgrade cockpit-doc | May 18, 2022 | Aug 27, 2021 |
| Redhat_linux | — | Upgrade cockpit-systemUpgrade cockpit-docUpgrade cockpit-debugsourceUpgrade cockpit-wsUpgrade cockpit-debuginfoUpgrade cockpitNo solution existsUpgrade cockpit-bridge | May 13, 2022 | Mar 10, 2022 |
| Rocky_linux | — | Upgrade cockpitUpgrade cockpit-bridgeUpgrade cockpit-debugsourceUpgrade cockpit-wsUpgrade cockpit-debuginfo | May 20, 2022 | Mar 10, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 10, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub