Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:3667

Опубликовано: 14 июн. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: cockpit security update

Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.

Security Fix(es):

  • cockpit: command injection when deleting a sosreport with a crafted name (CVE-2024-2947)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
cockpitx86_641.el8_10cockpit-310.4-1.el8_10.x86_64.rpm
cockpit-bridgex86_641.el8_10cockpit-bridge-310.4-1.el8_10.x86_64.rpm
cockpit-docnoarch1.el8_10cockpit-doc-310.4-1.el8_10.noarch.rpm
cockpit-systemnoarch1.el8_10cockpit-system-310.4-1.el8_10.noarch.rpm
cockpit-wsx86_641.el8_10cockpit-ws-310.4-1.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

CVSS3: 7.3
redhat
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

CVSS3: 7.3
nvd
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

CVSS3: 7.3
debian
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name ...

CVSS3: 7.3
github
около 1 года назад

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.