Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2947

Опубликовано: 27 мар. 2024
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

Отчет

The Cockpit package, as shipped in Red Hat Enterprise Linux 7, 8.2, 8.4, and 8.6, is not affected by this vulnerability because the vulnerable code was introduced in a newer version of Cockpit.

Меры по смягчению последствий

Do not remove SOS reports with strange names from the Cockpit web interface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7cockpitNot affected
Red Hat Enterprise Linux 8cockpitFixedRHSA-2024:366706.06.2024
Red Hat Enterprise Linux 9cockpitFixedRHSA-2024:384311.06.2024
Red Hat Enterprise Linux 9cockpitFixedRHSA-2024:384311.06.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2271614cockpit: command injection when deleting a sosreport with a crafted name

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

CVSS3: 7.3
nvd
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

CVSS3: 7.3
debian
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name ...

rocky
около 1 года назад

Moderate: cockpit security update

CVSS3: 7.3
github
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

7.3 High

CVSS3