Unrestricted Upload of File with Dangerous Type in cockpit-hq/cockpit
CVE-2023-1313

8.8HIGH

Key Information:

Vendor

Cockpit-hq

Vendor
CVE Published:
10 March 2023

What is CVE-2023-1313?

The vulnerability allows attackers to upload files of dangerous types in the Cockpit application, which could lead to various security incidents. This issue affects versions prior to 2.4.1 and arises from insufficient validation controls, enabling the potential execution of malicious files on the server.

Affected Version(s)

cockpit-hq/cockpit < 2.4.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.