CVE-2022-2818
published 2022-08-15CVE-2022-2818: Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
PriorityP341high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.28%
66.4th percentile
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| agentejo | cockpit | < 2.2.2 | 2.2.2 |
| cockpit-hq | cockpit | >= 0 < 2.2.2 | 2.2.2 |
| cockpit-hq | cockpit-hq_cockpit | >= unspecified < 2.2.2 | 2.2.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cockpit Content Platform vulnerable to 2FA bypass
ghsa·2022-08-16
CVE-2022-2818 [HIGH] CWE-212 Cockpit Content Platform vulnerable to 2FA bypass
Cockpit Content Platform vulnerable to 2FA bypass
Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the `develop` branch and is expected to be part of version 2.2.2.
OSV
Cockpit Content Platform vulnerable to 2FA bypass
osv·2022-08-16
CVE-2022-2818 [HIGH] Cockpit Content Platform vulnerable to 2FA bypass
Cockpit Content Platform vulnerable to 2FA bypass
Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the `develop` branch and is expected to be part of version 2.2.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-15
Published