Описание
ELSA-2026-21676: cockpit security update (IMPORTANT)
[356.2-1.0.1]
- Storage: Enable btrfs support [Orabug: 37464632]
- Replaced upstream urls in documentation with oracle links [Orabug: 36528753]
- Drop subscription-manager-cockpit requirement for ol [Orabug: 34681110]
- Remove duplicate reference to server in cockpit [Orabug: 34030494]
- Update documentation links [Orabug: 30271413], [Orabug: 32013095], [Orabug: 32795691], [Orabug: 34398512], [Orabug: 34742876], [Orabug: 37253273]
- Update spec file for new release
[356.1-1]
- ws: Prevent remote code execution with SSH argument injection (RHEL-158306)
- node: update lodash dependency (RHEL-164067)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
cockpit
356.2-1.0.1.el10_2
cockpit-bridge
356.2-1.0.1.el10_2
cockpit-doc
356.2-1.0.1.el10_2
cockpit-packagekit
356.2-1.0.1.el10_2
cockpit-storaged
356.2-1.0.1.el10_2
cockpit-system
356.2-1.0.1.el10_2
cockpit-ws
356.2-1.0.1.el10_2
cockpit-ws-selinux
356.2-1.0.1.el10_2
Oracle Linux x86_64
cockpit
356.2-1.0.1.el10_2
cockpit-bridge
356.2-1.0.1.el10_2
cockpit-doc
356.2-1.0.1.el10_2
cockpit-packagekit
356.2-1.0.1.el10_2
cockpit-storaged
356.2-1.0.1.el10_2
cockpit-system
356.2-1.0.1.el10_2
cockpit-ws
356.2-1.0.1.el10_2
cockpit-ws-selinux
356.2-1.0.1.el10_2
Связанные CVE
Связанные уязвимости
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
A flaw was found in Cockpit. This vulnerability allows a remote attack ...