CVE-2023-4433: Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Other sources
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit version 2.6.3 and prior. A patch is available at commit 36d1d4d256cbbab028342ba10cc493e5c119172c and anticipated to be part of version 2.6.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4433?
CVE-2023-4433 is a Cross-site Scripting (XSS) vulnerability that exists in the GitHub repository cockpit-hq/cockpit prior to version 2.6.4.
How severe is the CVE-2023-4433 vulnerability?
The severity of CVE-2023-4433 is rated as high with a CVSS score of 8.3.
Which software versions are affected by CVE-2023-4433?
The versions affected by CVE-2023-4433 are up to and including version 2.6.3 of the cockpit-hq/cockpit GitHub repository.
How can I fix the CVE-2023-4433 vulnerability?
To fix the CVE-2023-4433 vulnerability, you can apply the patch available at commit 36d1d4d256cbbab028342ba10cc493e5c119172c, which is anticipated to be part of version 2.6.4.
What is the CWE number associated with CVE-2023-4433?
The CWE number associated with CVE-2023-4433 is 79.