CVE-2019-3804Missing Initialization of Resource in Cockpit

Severity
7.5HIGHNVD
EPSS
4.3%
top 11.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateMay 13

Description

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gpg2-6gwq-vf2g: It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack2022-05-13
OSV
CVE-2019-3804: It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack2019-03-26
CVEList
CVE-2019-3804: It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack2019-03-26

📋Vendor Advisories

2
Debian
CVE-2019-3804: cockpit - It was found that cockpit before version 184 used glib's base64 decode functiona...2019
Red Hat
cockpit: Crash when parsing invalid base64 headers2018-12-13

💬Community

2
Bugzilla
CVE-2019-3804 cockpit: Crash when parsing invalid base64 headers [fedora-all]2019-01-07
Bugzilla
CVE-2019-3804 cockpit: Crash when parsing invalid base64 headers2019-01-04
CVE-2019-3804 — Missing Initialization of Resource | cvebase