CVE-2023-1313: Unrestricted Upload of File with Dangerous Type in cockpit-hq/cockpit
Published Mar 10, 2023
·Updated
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
Affected Software
1 affected component
Agentejo Cockpit<=2.4.0
Remediation
Event History
Mar 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1313?
The severity of CVE-2023-1313 is high (8.8).
2
What is CVE-2023-1313?
CVE-2023-1313 is an unrestricted upload of a file with a dangerous type vulnerability in the GitHub repository cockpit-hq/cockpit prior to version 2.4.1.
3
How does CVE-2023-1313 affect Agentejo Cockpit?
CVE-2023-1313 affects Agentejo Cockpit version up to and including 2.4.0.
4
How can I fix CVE-2023-1313?
To fix CVE-2023-1313, update Agentejo Cockpit to version 2.4.1 or later.
5
Is there any additional information available about CVE-2023-1313?
Additional information about CVE-2023-1313 can be found in the references: [GitHub Commit](https://github.com/cockpit-hq/cockpit/commit/becca806c7071ecc732521bb5ad0bb9c64299592), [Huntr Dev](https://huntr.dev/bounties/f73eef49-004f-4b3b-9717-90525e65ba61)