First published: Wed Feb 05 2025(Updated: )
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Cockpit | <2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1025 has a medium severity rating due to the potential for arbitrary file upload by unauthorized users.
To fix CVE-2025-1025, update the cockpit package to version 2.4.1 or later.
CVE-2025-1025 affects all versions of the cockpit package prior to 2.4.1.
CVE-2025-1025 is an arbitrary file upload vulnerability.
Yes, CVE-2025-1025 can be exploited remotely if an attacker successfully bypasses the upload filter.