High severity7.3NVD Advisory· Published Mar 28, 2024· Updated Apr 15, 2026
CVE-2024-2947
CVE-2024-2947
Description
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords9 versionspkg:deb/ubuntu/cockpit@314-1?arch=source&distro=oracularpkg:rpm/almalinux/cockpitpkg:rpm/almalinux/cockpit-bridgepkg:rpm/almalinux/cockpit-docpkg:rpm/almalinux/cockpit-packagekitpkg:rpm/almalinux/cockpit-pcppkg:rpm/almalinux/cockpit-storagedpkg:rpm/almalinux/cockpit-systempkg:rpm/almalinux/cockpit-ws
< 314-1+ 8 more
- (no CPE)range: < 314-1
- (no CPE)range: < 310.4-1.el8_10
- (no CPE)range: < 310.4-1.el8_10
- (no CPE)range: < 310.4-1.el8_10
- (no CPE)range: < 311.2-1.el9_4
- (no CPE)range: < 311.2-1.el9_4
- (no CPE)range: < 311.2-1.el9_4
- (no CPE)range: < 310.4-1.el8_10
- (no CPE)range: < 310.4-1.el8_10
Patches
Vulnerability mechanics
References
7- access.redhat.com/errata/RHSA-2024:3667nvd
- access.redhat.com/errata/RHSA-2024:3843nvd
- access.redhat.com/security/cve/CVE-2024-2947nvd
- bugzilla.redhat.com/show_bug.cginvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNG7GXOZI6QH3OIQJYAYDB3CRRGH37Q5/nvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N3Q5SDIFACAY4VHACN5MMCMT3A53A3FB/nvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PIQY2HGDJW2JY27ALTS4GEVZZJJ4XQ36/nvd
News mentions
0No linked articles in our index yet.