CVE-2023-4195: PHP Remote File Inclusion in cockpit-hq/cockpit
Published Aug 6, 2023
·Updated
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
Affected Software
2 affected componentsFixes available
composer/cockpit-hq/cockpit<2.6.3
2.6.3
Agentejo Cockpit<2.6.3
Remediation
Event History
Aug 6, 2023
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
06:15 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is CVE-2023-4195?
CVE-2023-4195 is a vulnerability that allows for PHP Remote File Inclusion in the GitHub repository cockpit-hq/cockpit prior to version 2.6.3.
2
How does CVE-2023-4195 work?
CVE-2023-4195 works by allowing users to upload php files through the system file upload utility, which can then be used to execute remote code.
3
How severe is CVE-2023-4195?
CVE-2023-4195 has a severity keyword of 'critical' and a severity value of 9.9.
4
Which software versions are affected by CVE-2023-4195?
Versions of the GitHub repository cockpit-hq/cockpit prior to 2.6.3 and Agentejo Cockpit up to version 2.6.3 are affected by CVE-2023-4195.
5
How can I fix CVE-2023-4195?
To fix CVE-2023-4195, update to version 2.6.3 of the cockpit-hq/cockpit GitHub repository or Agentejo Cockpit.