See how cockpit-project compares to other vendors in security performance
A flaw was found in cockpit web server that may lead to denial of server through sending crafted invalid base64 headers.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1659542
Upstream issue:
https://github.com/cockpit-project/cockpit/pull/10819
Upstream patch:
https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12
A flaw was found in Cockpit in the way it handles the certificate verification performed by SSSD and allows client certificates to successfully authenticate regardless of the CRL configuration or the certificate status.
DISPUTED An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue."
Cockpit (and its plugins) do not seem to protect itself against clickjacking : it is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry.
This may be used by a malicious website in clickjacking, or similar, attacks.
To prevent this behavior, a X-Frame-Options header could be added to the responses.