CVE-2021-3660
published 2022-03-10CVE-2021-3660: Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside…
medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| agentejo | cockpit | >= 0 < 254-1 | 254-1 |
| agentejo | cockpit | >= 0 < 254-1 | 254-1 |
| agentejo | cockpit | >= 0 < 254-1 | 254-1 |
| cockpit-project | cockpit | < 254 | 254 |
| cockpit-project | cockpit | — | — |
| debian | cockpit | < cockpit 254-1 (bookworm) | cockpit 254-1 (bookworm) |
| msrc | cm1_cockpit_248-3_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv4.3MEDIUM
Microsoft
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used
vendor_msrc·2022-03-08·CVSS 4.3
CVE-2021-3660 [MEDIUM] CWE-1021 Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to addi
Red Hat
cockpit: pages vulnerable to clickjacking
vendor_redhat·2021-07-20·CVSS 4.3
CVE-2021-3660 [MEDIUM] CWE-1021 cockpit: pages vulnerable to clickjacking
cockpit: pages vulnerable to clickjacking
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Statement: In cockpit versions 236 and above (Red Hat Enterprise Linux 8.4 and above), this flaw should not be exploitable, as the session cookie has the `SameSite=Strict;` option enabled, preventing the Web Browsers to reuse it from 3rd party web sites
Debian
CVE-2021-3660: cockpit - Cockpit (and its plugins) do not seem to protect itself against clickjacking. It...
vendor_debian·2021·CVSS 4.3
CVE-2021-3660 [MEDIUM] CVE-2021-3660: cockpit - Cockpit (and its plugins) do not seem to protect itself against clickjacking. It...
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Scope: local
bookworm: resolved (fixed in 254-1)
bullseye: open
forky: resolved (fixed in 254-1)
sid: resolved (fixed in 254-1)
trixie: resolved (fixed in 254-1)
GHSA
GHSA-5m9v-2hhc-h2wj: Cockpit (and its plugins) do not seem to protect itself against clickjacking
ghsa_unreviewed·2022-03-11
CVE-2021-3660 [MEDIUM] CWE-1021 GHSA-5m9v-2hhc-h2wj: Cockpit (and its plugins) do not seem to protect itself against clickjacking
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
OSV
CVE-2021-3660: Cockpit (and its plugins) do not seem to protect itself against clickjacking
osv·2022-03-10·CVSS 4.3
CVE-2021-3660 [MEDIUM] CVE-2021-3660: Cockpit (and its plugins) do not seem to protect itself against clickjacking
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1980688https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10https://github.com/cockpit-project/cockpit/issues/16122https://bugzilla.redhat.com/show_bug.cgi?id=1980688https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10https://github.com/cockpit-project/cockpit/issues/16122
2022-03-10
Published