A flaw was found in Cockpit. Deleting a sosreport with a...
High severity
Unreviewed
Published
Mar 28, 2024
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Mar 28, 2024
Published to the GitHub Advisory Database
Mar 28, 2024
Last updated
Mar 30, 2024
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
References