CVE-2023-4432: Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit
Published Aug 19, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Other sources
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit version 2.6.3 and prior. A patch is available at commit 2a93d391fbd2dd9e730f65d43b29beb65903d195 and anticipated to be part of version 2.6.4.
Affected Software
2 affected components
composer/cockpit-hq/cockpit<=2.6.3
Agentejo Cockpit<=2.6.3
Remediation
Event History
Aug 19, 2023
CVE Published
via MITRE·12:52 AM
Data Sourced
via MITRE·12:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-4432?
The severity of CVE-2023-4432 is high.
2
How does CVE-2023-4432 impact GitHub repository cockpit-hq/cockpit?
CVE-2023-4432 impacts GitHub repository cockpit-hq/cockpit by enabling cross-site scripting (XSS) attacks.
3
What version of cockpit-hq/cockpit is affected by CVE-2023-4432?
Cockpit-hq/cockpit version 2.6.3 and prior is affected by CVE-2023-4432.
4
How can I fix CVE-2023-4432?
To fix CVE-2023-4432, update to version 2.6.4 or apply the patch available at commit 2a93d391fbd2dd9e730f65d43b29beb65903d195.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-4432?
The CWE ID for CVE-2023-4432 is CWE-79.