Описание
ELSA-2022-2008: cockpit security, bug fix, and enhancement update (MODERATE)
[264.1-1.0.1]
- Remove duplicate reference to server in cockpit [Orabug: 33862832]
- Update documentation links [Orabug: 32795691]
- Make documentation links point to Oracle Linux information [Orabug: 30271413] [Orabug: 32013095]
- Fix rendering of hwinfo page on systems with some empty memory slots [Orabug: 32826970]
[264.1-1]
- metrics: Fix link construction for user services
- Translation updates (rhbz#2016998)
[264-1]
- Metrics: Improve layout on small resolutions
- Networking: Fix checkpoint handling and IP settings dialog (rhbz#2056386)
- Services: Show error message instead of eternal 'Loading...' state
- Accounts: Add override button to confirm weak password
- Accounts: Fix parsing of 'last login' date
[263-1]
- Overview: Show scheduled shutdowns
- Networking: Add firewall service description
- Shell: Fix browser history
[261-1]
- shell: Allow adding keys with passphrase
[260-1]
- Certificate login validation (rhbz#1992620, CVE-2021-3698)
- Client: Show previously used hosts
- Client: Support port specification
- bridge: Warning on missing cockpit-system package
[259-1]
- Translation updates
[258-1]
- Tweak login screen UI
- Fix SELinux policy installation
[257-1]
- Support for reading TLS certificates with any permissions
- cockpit-ws no longer supports merged certificates
- Services: Show user-owned systemd units (rhbz#1792270)
[255-1]
- Restrict frame embedding to same origin (rhbz#1984902, CVE-2021-3660)
- kdump: Show 'Directory' field for NFS mounts (rbhz#2004041)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
cockpit
264.1-1.0.1.el8
cockpit-bridge
264.1-1.0.1.el8
cockpit-doc
264.1-1.0.1.el8
cockpit-system
264.1-1.0.1.el8
cockpit-ws
264.1-1.0.1.el8
Oracle Linux x86_64
cockpit
264.1-1.0.1.el8
cockpit-bridge
264.1-1.0.1.el8
cockpit-doc
264.1-1.0.1.el8
cockpit-system
264.1-1.0.1.el8
cockpit-ws
264.1-1.0.1.el8
Связанные CVE
Связанные уязвимости
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Cockpit (and its plugins) do not seem to protect itself against clickj ...