Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown

CVE-2022-2713

Disclosure Date: August 08, 2022 (last updated October 08, 2023)
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
Attacker Value
Unknown

CVE-2021-3698

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
Attacker Value
Unknown

CVE-2021-3660

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Attacker Value
Unknown

CVE-2020-35131

Disclosure Date: January 08, 2021 (last updated February 22, 2025)
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
Attacker Value
Unknown

CVE-2020-35850

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
Attacker Value
Unknown

CVE-2020-35848

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Attacker Value
Unknown

CVE-2020-14408

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
Attacker Value
Unknown

CVE-2020-6252

Disclosure Date: May 12, 2020 (last updated November 27, 2024)
Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability.
Attacker Value
Unknown

CVE-2020-10788

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
Attacker Value
Unknown

CVE-2020-10791

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.