CVE-2020-35850: SSRF
Published Dec 30, 2020
·Updated
DISPUTED An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue."
Affected Software
1 affected component
cockpit-project cockpit=234
Event History
Dec 30, 2020
CVE Published
via MITRE·01:27 AM
Data Sourced
via MITRE·01:27 AM
Description
Disputed
02:15 AM
Frequently Asked Questions
1
What is the vulnerability ID for this SSRF issue in cockpit-project.org Cockpit 234?
The vulnerability ID for this SSRF issue in cockpit-project.org Cockpit 234 is CVE-2020-35850.
2
What is the severity of CVE-2020-35850?
The severity of CVE-2020-35850 is medium with a CVSS score of 6.5.
3
What software version is affected by CVE-2020-35850?
Cockpit 234 is affected by CVE-2020-35850.
4
Is there a fix available for CVE-2020-35850?
There is no fix available for this vulnerability as it is disputed by the vendor.
5
Where can I find more information about CVE-2020-35850?
You can find more information about CVE-2020-35850 in the references: [Link 1](https://github.com/cockpit-project/cockpit/issues/15077), [Link 2](https://github.com/passtheticket/vulnerability-research/blob/main/cockpitProject/README.md).