Cockpit · Cockpit · CVE-2021-3660
**Name of the Vulnerable Software and Affected Versions**
Cockpit (affected versions not specified)
**Description**
The issue is related to clickjacking attacks, where a malicious website can render a page from a Cockpit server inside an `iframe` HTML entry. This could be exploited by a malicious website to perform clickjacking or similar attacks. The vulnerability is also associated with errors in displaying the user interface or frames, which could allow a remote attacker to inject malicious code.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.