Количество 12
Количество 12
BDU:2026-05259
Уязвимость системы управления серверами Cockpit, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
CVE-2026-4631
Cockpit's remote login feature passes user-supplied hostnames and user ...
openSUSE-SU-2026:20523-1
Security update for cockpit
RLSA-2026:7384
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
RLSA-2026:7383
Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection
GHSA-rq49-h582-83m7
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.
ELSA-2026-7384
ELSA-2026-7384: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL)
ELSA-2026-7383
ELSA-2026-7383: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL)
openSUSE-SU-2026:21399-1
Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-05259 Уязвимость системы управления серверами Cockpit, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
CVE-2026-4631 Cockpit's remote login feature passes user-supplied hostnames and user ... | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
openSUSE-SU-2026:20523-1 Security update for cockpit | 14% Средний | 4 месяца назад | ||
RLSA-2026:7384 Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection | 14% Средний | 2 месяца назад | ||
RLSA-2026:7383 Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection | 14% Средний | 2 месяца назад | ||
GHSA-rq49-h582-83m7 Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability. | CVSS3: 9.8 | 14% Средний | 4 месяца назад | |
ELSA-2026-7384 ELSA-2026-7384: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL) | 4 месяца назад | |||
ELSA-2026-7383 ELSA-2026-7383: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection (CRITICAL) | 4 месяца назад | |||
openSUSE-SU-2026:21399-1 Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions | 10 дней назад |
Уязвимостей на страницу