← Back

Getcockpit

getcockpit

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Cockpit
cockpit

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Getcockpit
1Cockpit
Nov 21, 2024
May 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cockpit 0.5.5 has XSS via a collection, form, or region.
1Getcockpit
1Cockpit
Nov 21, 2024
May 2, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerab...Show more
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.Show less