Arbitrary File Upload Vulnerability in Cockpit by Cockpit HQ
CVE-2025-1025

8.7HIGH

Key Information:

Vendor

Cockpit HQ

Vendor
CVE Published:
5 February 2025

What is CVE-2025-1025?

Certain versions of Cockpit, specifically those prior to 2.4.1, are susceptible to an Arbitrary File Upload vulnerability. This flaw allows attackers to leverage alternative file extensions to circumvent existing upload filters, potentially leading to unsecured file uploads on the server. By exploiting this vulnerability, an attacker could upload malicious files, posing significant risks to the integrity and security of the affected systems.

Affected Version(s)

cockpit-hq/cockpit 0 < 2.4.1

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chi Siang Choo
.