CVE-2024-2947
EUVD-2024-2788928.03.2024, 19:15
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| cockpit |
| ||||
| cockpit-bridge |
| ||||
| cockpit-doc |
| ||||
| cockpit-packagekit |
| ||||
| cockpit-pcp |
| ||||
| cockpit-storaged |
| ||||
| cockpit-system |
| ||||
| cockpit-ws |
|
References