First published: Wed Dec 30 2020(Updated: )
** DISPUTED ** An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cockpit-project Cockpit | =234 | |
=234 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SSRF issue in cockpit-project.org Cockpit 234 is CVE-2020-35850.
The severity of CVE-2020-35850 is medium with a CVSS score of 6.5.
Cockpit 234 is affected by CVE-2020-35850.
There is no fix available for this vulnerability as it is disputed by the vendor.
You can find more information about CVE-2020-35850 in the references: [Link 1](https://github.com/cockpit-project/cockpit/issues/15077), [Link 2](https://github.com/passtheticket/vulnerability-research/blob/main/cockpitProject/README.md).