Логотип exploitDog
bind:"CVE-2021-3660" OR bind:"CVE-2021-3698"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-3660" OR bind:"CVE-2021-3698"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2022-2008

больше 3 лет назад

ELSA-2022-2008: cockpit security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-3660

почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-3660

больше 4 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-3660

почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2021-3660

почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-3660

почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickj ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-3698

почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-3698

больше 4 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-3698

почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3698

почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-3698

почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it han ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5m9v-2hhc-h2wj

почти 4 года назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2021-04029

больше 4 лет назад

Уязвимость менеджера для серверов Cockpit, связанная с ошибками при отображении пользовательского интерфейса или фреймов, позволяющая нарушителю внедрить вредоносный код

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20260129-73-0009

12 дней назад

Уязвимость cockpit

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:2008

больше 3 лет назад

Moderate: cockpit security, bug fix, and enhancement update

EPSS: Низкий
github логотип

GHSA-w9ph-5m4x-c49r

почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-2008

ELSA-2022-2008: cockpit security, bug fix, and enhancement update (MODERATE)

больше 3 лет назад
ubuntu логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickj ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it han ...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-5m9v-2hhc-h2wj

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2021-04029

Уязвимость менеджера для серверов Cockpit, связанная с ошибками при отображении пользовательского интерфейса или фреймов, позволяющая нарушителю внедрить вредоносный код

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
redos логотип
ROS-20260129-73-0009

Уязвимость cockpit

CVSS3: 7.5
0%
Низкий
12 дней назад
rocky логотип
RLSA-2022:2008

Moderate: cockpit security, bug fix, and enhancement update

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w9ph-5m4x-c49r

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу