It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
2019-03-26T18:29:00.543
2024-11-21T04:42:34.493
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cockpit-project | cockpit | < 184 | Yes |
Operating System | fedoraproject | fedora | - | Yes |
Application | redhat | virtualization | 4.0 | Yes |