Agentejo Cockpit vulnerabilities

33 known vulnerabilities affecting agentejo/cockpit.

Total CVEs
33
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH9MEDIUM16LOW1

Vulnerabilities

Page 2 of 2
CVE-2023-0780MEDIUMCVSS 5.4fixed in 2.3.92023-02-11
CVE-2023-0780 [MEDIUM] CWE-1021 CVE-2023-0780: Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior t Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.
nvd
CVE-2023-0759HIGHCVSS 8.8fixed in 2.3.82023-02-09
CVE-2023-0759 [HIGH] CWE-268 CVE-2023-0759: Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
nvd
CVE-2022-2818HIGHCVSS 8.8fixed in 2.2.22022-08-15
CVE-2022-2818 [HIGH] CWE-212 CVE-2022-2818: Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
nvd
CVE-2022-2713CRITICALCVSS 9.8fixed in 2.2.02022-08-08
CVE-2022-2713 [CRITICAL] CWE-613 CVE-2022-2713: Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
nvd
CVE-2021-3698HIGHCVSS 7.5vcockpit versions prior to 2602022-03-08
CVE-2021-3698 [HIGH] CWE-295 CVE-2021-3698: A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daem A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the cert
cvelistv5osv
CVE-2021-3660MEDIUMCVSS 4.3vFixed in cockpit v254 and later.2022-03-07
CVE-2021-3660 [MEDIUM] CWE-1021 CVE-2021-3660: Cockpit (and its plugins) do not seem to protect itself against clickjacking Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
cvelistv5osv
CVE-2020-35131CRITICALCVSS 9.8PoCfixed in 0.6.12021-01-08
CVE-2020-35131 [CRITICAL] CWE-94 CVE-2020-35131: Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Executi Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
nvd
CVE-2020-35847CRITICALCVSS 9.8PoCfixed in 0.11.22020-12-30
CVE-2020-35847 [CRITICAL] CWE-89 CVE-2020-35847: Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword func Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
nvd
CVE-2020-35848CRITICALCVSS 9.8PoCfixed in 0.11.22020-12-30
CVE-2020-35848 [CRITICAL] CWE-89 CVE-2020-35848: Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword functi Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
nvd
CVE-2020-35846CRITICALCVSS 9.8PoCfixed in 0.11.22020-12-30
CVE-2020-35846 [CRITICAL] CWE-89 CVE-2020-35846: Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
nvd
CVE-2020-14408MEDIUMCVSS 6.1PoCv0.10.22020-06-17
CVE-2020-14408 [MEDIUM] CWE-79 CVE-2020-14408: An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
nvd
CVE-2019-3804HIGHCVSS 7.5≥ 0, < 184-12019-03-26
CVE-2019-3804 [HIGH] CVE-2019-3804: It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
osv
CVE-2017-14611CRITICALCVSS 9.1v0.13.02018-04-10
CVE-2017-14611 [CRITICAL] CWE-918 CVE-2017-14611: SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
nvd