Vulnerabilities
Vulnerable Software
Cockpit-Project:  >> Cockpit  >> 186  Security Vulnerabilities
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-03-10
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
CVSS Score
4.3
EPSS Score
0.003
Published
2022-03-10


Contact Us

Shodan ® - All rights reserved