CVE-2023-4451: Cross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.
Other sources
Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit version 2.6.3 and prior. A patch is available at commit 30609466c817e39f9de1871559603e93cd4d0d0c and anticipated to be part of version 2.6.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4451?
CVE-2023-4451 is a Cross-site Scripting (XSS) vulnerability that was found in the GitHub repository cockpit-hq/cockpit prior to version 2.6.4.
How severe is CVE-2023-4451?
CVE-2023-4451 has a severity rating of 6.1, which is medium.
What is the affected software for CVE-2023-4451?
The affected software for CVE-2023-4451 is cockpit-hq/cockpit version 2.6.3 and prior.
How can I fix CVE-2023-4451?
To fix CVE-2023-4451, update your cockpit-hq/cockpit software to version 2.6.4 or later.
Where can I find more information about CVE-2023-4451?
You can find more information about CVE-2023-4451 at the following references: [GitHub Commit](https://github.com/cockpit-hq/cockpit/commit/30609466c817e39f9de1871559603e93cd4d0d0c), [Huntr Bounty](https://huntr.dev/bounties/4e111c3e-6cf3-4b4c-b3c1-a540bf30f8fa), and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-4451).