High severity7.5OSV Advisory· Published Mar 26, 2019· Updated Jun 17, 2026
CVE-2019-3804
CVE-2019-3804
Description
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*
- Range: <184
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/cockpit-project/cockpit/commit/c51f6177576d7e12nvdPatchThird Party Advisory
- access.redhat.com/errata/RHSA-2019:1569nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2019:1571nvdThird Party Advisory
- github.com/cockpit-project/cockpit/pull/10819nvdThird Party Advisory
News mentions
0No linked articles in our index yet.