PT-2023-16885 · Cockpit Hq · Cockpit

Published

2023-03-10

·

Updated

2023-09-28

·

CVE-2023-1313

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cockpit-hq/cockpit versions prior to 2.4.1
Description The issue concerns an unrestricted upload of files with dangerous types. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-1313
GHSA-6X8F-X6QW-QWX3

Affected Products

Cockpit