Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wj3-cpmr-8whp

Опубликовано: 16 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Cockpit Content Platform vulnerable to 2FA bypass

Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the develop branch and is expected to be part of version 2.2.2.

Пакеты

Наименование

cockpit-hq/cockpit

composer
Затронутые версииВерсия исправления

<= 2.2.1

2.2.2

EPSS

Процентиль: 80%
0.01424
Низкий

8.8 High

CVSS3

Дефекты

CWE-212
CWE-287
CWE-305

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

EPSS

Процентиль: 80%
0.01424
Низкий

8.8 High

CVSS3

Дефекты

CWE-212
CWE-287
CWE-305