First published: Fri Jul 09 2021(Updated: )
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cockpit-project Cockpit | <254 | |
Redhat Enterprise Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3660 is a vulnerability in Cockpit (and its plugins) that allows clickjacking attacks.
CVE-2021-3660 allows a malicious website to render a page from a Cockpit server via an <iFrame> HTML entry, enabling clickjacking or similar attacks.
CVE-2021-3660 affects all versions up to 254 of Cockpit and Redhat Enterprise Linux 8.0.
CVE-2021-3660 has a severity rating of medium, with a CVSS score of 4.3.
To protect against CVE-2021-3660, ensure that your Cockpit installation implements X-Frame-Options to prevent clickjacking attacks.