Описание
ELSA-2026-21468: cockpit security update (IMPORTANT)
[356.2-1.0.1]
- Apply the patch for duplicate reference [Orabug: 39250109]
- Storage: Enable btrfs support [Orabug: 37464632]
- Replaced upstream urls in documentation with oracle links [Orabug: 36528753]
- Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110]
- Remove duplicate reference to server in cockpit [Orabug: 34030494]
- Update documentation links [Orabug: 30271413], [Orabug: 32013095], [Orabug: 32795691], [Orabug: 34398512], [Orabug: 34742876], [Orabug: 37253273]
- Update spec file for new release
[356.2]
- Remove recommends on subscription-manager-cockpit if applicable
[356.1-1]
- ws: Prevent remote code execution with SSH argument injection (RHEL-158310)
- node: update lodash dependency (RHEL-164196)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
cockpit
356.2-1.0.1.el9_8
cockpit-bridge
356.2-1.0.1.el9_8
cockpit-doc
356.2-1.0.1.el9_8
cockpit-packagekit
356.2-1.0.1.el9_8
cockpit-storaged
356.2-1.0.1.el9_8
cockpit-system
356.2-1.0.1.el9_8
cockpit-ws
356.2-1.0.1.el9_8
cockpit-ws-selinux
356.2-1.0.1.el9_8
Oracle Linux x86_64
cockpit
356.2-1.0.1.el9_8
cockpit-bridge
356.2-1.0.1.el9_8
cockpit-doc
356.2-1.0.1.el9_8
cockpit-packagekit
356.2-1.0.1.el9_8
cockpit-storaged
356.2-1.0.1.el9_8
cockpit-system
356.2-1.0.1.el9_8
cockpit-ws
356.2-1.0.1.el9_8
cockpit-ws-selinux
356.2-1.0.1.el9_8
Связанные CVE
Связанные уязвимости
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attack ...