VYPR

Cockpit

by Agentejo

Source repositories

CVEs (42)

  • CVE-2021-3660MedMar 10, 2022
    risk 0.00cvss 4.3epss 0.01

    Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

  • CVE-2019-3804HigMar 26, 2019
    risk 0.00cvss 7.5epss 0.05

    It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to…

Page 3 of 3