Logo
componentcockpit
Name
cockpit
Version
220
Type
library
Description
Admin interface for Linux machines
Licenses
LGPL-2.1-only
PURL
-
CPE
cpe:2.3:*:cockpit-project:cockpit:220:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
352
scarthgap
304

Vulnerabilities#


Name
Analysis
Description
Exploitable
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
Exploitable
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.