CVE-2024-2947

CVSS V2 None CVSS V3 None
Description
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
Overview
  • CVE ID
  • CVE-2024-2947
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-28T18:31:59.249Z
  • Last Modified Date
  • 2024-06-12T09:00:56.231Z
History
Created Old Value New Value Data Type Notes
2024-06-25 23:58:41 Added to TrackCVE