A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade cockpit-pcpUpgrade cockpit-systemUpgrade cockpitUpgrade cockpit-packagekitUpgrade cockpit-bridgeUpgrade cockpit-docUpgrade cockpit-wsUpgrade cockpit-storaged | Jun 7, 2024 | Mar 28, 2024 |
| Debian | — | Upgrade cockpit | Apr 8, 2024 | Mar 28, 2024 |
| Oracle_linux | — | Upgrade cockpit-packagekitUpgrade cockpit-bridgeUpgrade cockpitUpgrade cockpit-storagedUpgrade cockpit-wsUpgrade cockpit-systemUpgrade cockpit-docUpgrade cockpit-pcp | Jun 6, 2024 | Mar 27, 2024 |
| Redhat_linux | — | Upgrade cockpit-systemUpgrade cockpit-debugsourceUpgrade cockpit-docUpgrade cockpit-storagedUpgrade cockpit-packagekitUpgrade cockpit-wsUpgrade cockpitUpgrade cockpit-pcpUpgrade cockpit-bridgeUpgrade cockpit-debuginfo | Jun 7, 2024 | Mar 28, 2024 |
| Rocky_linux | — | Upgrade cockpit-debuginfoUpgrade cockpit-wsUpgrade cockpit-debugsourceUpgrade cockpit-bridgeUpgrade cockpit | Jun 17, 2024 | Mar 28, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub