Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
2022-03-10T17:42:55.647
2024-11-21T06:22:05.833
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cockpit-project | cockpit | < 254 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |