Arbitrary Command Injection Affecting cockpit-project/cockpit package, versions [270,314)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.19% (65th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-COCKPITPROJECTCOCKPIT-6513177
  • published29 Mar 2024
  • disclosed27 Mar 2024
  • creditMartin Pitt

Introduced: 27 Mar 2024

CVE-2024-2947  (opens in a new tab)
CWE-77  (opens in a new tab)

How to fix?

Upgrade cockpit-project/cockpit to version 314 or higher.

Overview

Affected versions of this package are vulnerable to Arbitrary Command Injection during the deletion of a sosreport via a specially crafted name through the web interface. An attacker can achieve privilege escalation by executing arbitrary commands on the system.

CVSS Base Scores

version 3.1