漏洞信息详情
Cockpit 安全漏洞
漏洞简介
Cockpit是一个交互式服务器管理界面。
Cockpit中存在安全漏洞。攻击者可通过发送带有无效的base64加密cookie的请求利用该漏洞造成绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1571
来源:github.com
链接:https://github.com/cockpit-project/cockpit/pull/10819
来源:github.com
链接:https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3804
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1569
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1569
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:0482
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-3804
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/153363/Red-Hat-Security-Advisory-2019-1571-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/77066
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Cockpit-denial-of-service-via-Base64-Headers-28744
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2222/
受影响实体
暂无
补丁
- Cockpit 安全漏洞的修复措施<!--2019-3-13-->
还没有评论,来说两句吧...