CVE-2023-4395: Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit 2.6.3 and prior. A patch is available at commit 36d1d4d256cbbab028342ba10cc493e5c119172c and anticipated to be part of version 2.6.4.
Other sources
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4395?
CVE-2023-4395 is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
What is the severity of CVE-2023-4395?
The severity of CVE-2023-4395 is high, with a severity value of 8.1.
How does CVE-2023-4395 affect the Cockpit software?
CVE-2023-4395 affects the Cockpit software versions prior to 2.6.4, allowing for stored cross-site scripting (XSS) attacks.
Is there a patch available for CVE-2023-4395?
Yes, a patch is available at commit 36d1d4d256cbbab028342ba10cc493e5c119172c and is expected to be part of version 2.6.4.
Where can I find more information about CVE-2023-4395?
You can find more information about CVE-2023-4395 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-4395), [GitHub commit](https://github.com/cockpit-hq/cockpit/commit/36d1d4d256cbbab028342ba10cc493e5c119172c), [Huntr bounty](https://huntr.dev/bounties/60e38563-7ac8-4a13-ac04-2980cc48b0da).