Logo
vulnerabilityCVE-2021-3660
Name
CVE-2021-3660
Source
NVD ( link)Debian ( link)
Description
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
cockpit
Exploitable

Vulnerability Ratings#


4.3
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
352
Not Affected
yocto
scarthgap
304
Not Affected