CVE-2023-4422: Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published Aug 18, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
Affected Software
2 affected componentsFixes available
composer/cockpit-hq/cockpit<2.6.3
2.6.3
Agentejo Cockpit<2.6.3
Remediation
Event History
Aug 18, 2023
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-4422?
CVE-2023-4422 is a vulnerability related to Cross-site Scripting (XSS) that was found in the GitHub repository cockpit-hq/cockpit prior to version 2.6.3.
2
How severe is CVE-2023-4422?
CVE-2023-4422 has a severity level of 6.8 (medium).
3
What software is affected by CVE-2023-4422?
The software affected by CVE-2023-4422 includes the GitHub repository cockpit-hq/cockpit prior to version 2.6.3 and Agentejo Cockpit up to version 2.6.3.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2023-4422.
5
How can I fix CVE-2023-4422?
To fix CVE-2023-4422, you need to update your cockpit-hq/cockpit software to version 2.6.3 or higher.