CVE-2023-4321: Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published Aug 14, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit 2.6.2 and prior. A patch is available at commit 34ab31ee9362da51b9709e178469dbffd7717249.
Other sources
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.
Affected Software
2 affected components
composer/cockpit-hq/cockpit<=2.6.2
Agentejo Cockpit<2.4.3
Remediation
Event History
Aug 14, 2023
CVE Published
via MITRE·10:26 AM
Data Sourced
via MITRE·10:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
12:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-4321?
The severity of CVE-2023-4321 is high with a severity value of 8.3.
2
What is the description of CVE-2023-4321?
CVE-2023-4321 is a Cross-site Scripting (XSS) vulnerability that is stored in the GitHub repository cockpit-hq/cockpit prior to version 2.4.3.
3
Which software versions are affected by CVE-2023-4321?
Versions prior to 2.4.3 of cockpit-hq/cockpit and versions up to 2.6.2 of Agentejo Cockpit are affected by CVE-2023-4321.
4
Is there a patch available for CVE-2023-4321?
Yes, a patch is available at commit 34ab31ee9362da51b9709e178469dbffd7717249.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-4321?
The CWE ID for CVE-2023-4321 is 79.