Логотип exploitDog
bind:"CVE-2021-3660" OR bind:"CVE-2021-3698"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-3660" OR bind:"CVE-2021-3698"

Количество 15

Количество 15

oracle-oval логотип

ELSA-2022-2008

около 3 лет назад

ELSA-2022-2008: cockpit security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-3698

больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-3698

почти 4 года назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-3698

больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3698

больше 3 лет назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-3698

больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it han ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2021-3660

больше 3 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-3660

около 4 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-3660

больше 3 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2021-3660

больше 3 лет назад

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-3660

больше 3 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickj ...

CVSS3: 4.3
EPSS: Низкий
rocky логотип

RLSA-2022:2008

около 3 лет назад

Moderate: cockpit security, bug fix, and enhancement update

EPSS: Низкий
github логотип

GHSA-w9ph-5m4x-c49r

больше 3 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5m9v-2hhc-h2wj

больше 3 лет назад

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2021-04029

около 4 лет назад

Уязвимость менеджера для серверов Cockpit, связанная с ошибками при отображении пользовательского интерфейса или фреймов, позволяющая нарушителю внедрить вредоносный код

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-2008

ELSA-2022-2008: cockpit security, bug fix, and enhancement update (MODERATE)

около 3 лет назад
ubuntu логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it han ...

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-3660

Cockpit (and its plugins) do not seem to protect itself against clickj ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:2008

Moderate: cockpit security, bug fix, and enhancement update

0%
Низкий
около 3 лет назад
github логотип
GHSA-w9ph-5m4x-c49r

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-5m9v-2hhc-h2wj

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-04029

Уязвимость менеджера для серверов Cockpit, связанная с ошибками при отображении пользовательского интерфейса или фреймов, позволяющая нарушителю внедрить вредоносный код

CVSS3: 4.3
0%
Низкий
около 4 лет назад

Уязвимостей на страницу