VDB
CVE-2021-3660
CVE-2021-3660
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
EPSS 0.27% · 50.7th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.27%
50.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cockpit-project | cockpit | 0 |
| redhat | enterprise_linux | 8.0 |
| n/a | cockpit | Fixed in cockpit v254 and later. |
Timeline
- Mar 7, 2022 CVE Published
- Mar 8, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 19, 2022 EPSS Score
- Aug 10, 2022 EPSS Score
- Oct 1, 2022 EPSS Score
- Nov 21, 2022 EPSS Score
- Jan 12, 2023 EPSS Score
- Mar 4, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 25, 2023 EPSS Score
- Jun 15, 2023 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1980688 url
- https://github.com/cockpit-project/cockpit/issues/16122 url
- https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-3660 advisory
- https://access.redhat.com/errata/RHSA-2022:2008 url
- https://access.redhat.com/security/cve/CVE-2021-3660 url