Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-2008

Опубликовано: 17 мая 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-2008: cockpit security, bug fix, and enhancement update (MODERATE)

[264.1-1.0.1]

  • Remove duplicate reference to server in cockpit [Orabug: 33862832]
  • Update documentation links [Orabug: 32795691]
  • Make documentation links point to Oracle Linux information [Orabug: 30271413] [Orabug: 32013095]
  • Fix rendering of hwinfo page on systems with some empty memory slots [Orabug: 32826970]

[264.1-1]

  • metrics: Fix link construction for user services
  • Translation updates (rhbz#2016998)

[264-1]

  • Metrics: Improve layout on small resolutions
  • Networking: Fix checkpoint handling and IP settings dialog (rhbz#2056386)
  • Services: Show error message instead of eternal 'Loading...' state
  • Accounts: Add override button to confirm weak password
  • Accounts: Fix parsing of 'last login' date

[263-1]

  • Overview: Show scheduled shutdowns
  • Networking: Add firewall service description
  • Shell: Fix browser history

[261-1]

  • shell: Allow adding keys with passphrase

[260-1]

  • Certificate login validation (rhbz#1992620, CVE-2021-3698)
  • Client: Show previously used hosts
  • Client: Support port specification
  • bridge: Warning on missing cockpit-system package

[259-1]

  • Translation updates

[258-1]

  • Tweak login screen UI
  • Fix SELinux policy installation

[257-1]

  • Support for reading TLS certificates with any permissions
  • cockpit-ws no longer supports merged certificates
  • Services: Show user-owned systemd units (rhbz#1792270)

[255-1]

  • Restrict frame embedding to same origin (rhbz#1984902, CVE-2021-3660)
  • kdump: Show 'Directory' field for NFS mounts (rbhz#2004041)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

cockpit

264.1-1.0.1.el8

cockpit-bridge

264.1-1.0.1.el8

cockpit-doc

264.1-1.0.1.el8

cockpit-system

264.1-1.0.1.el8

cockpit-ws

264.1-1.0.1.el8

Oracle Linux x86_64

cockpit

264.1-1.0.1.el8

cockpit-bridge

264.1-1.0.1.el8

cockpit-doc

264.1-1.0.1.el8

cockpit-system

264.1-1.0.1.el8

cockpit-ws

264.1-1.0.1.el8

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
redhat
больше 4 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
nvd
почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
msrc
почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
debian
почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickj ...