
Cloud Vulnerability DB
A community-led vulnerabilities database
Unrestricted Upload of File with Dangerous Type vulnerability was discovered in GitHub repository cockpit-hq/cockpit versions prior to 2.4.1. The vulnerability was identified and assigned CVE-2023-1313 on March 10, 2023. This security flaw affected the assets manager component of the Cockpit application (NVD, CVE).
The vulnerability stems from insufficient file type validation in the assets manager component, specifically allowing the potential upload of PHP files. The issue was addressed in commit becca806c7071ecc732521bb5ad0bb9c64299592, which implemented additional security checks to prevent the upload of PHP files (GitHub Commit).
The vulnerability could allow attackers to upload malicious PHP files through the assets manager, potentially leading to remote code execution or other security compromises on affected systems (NVD).
The vulnerability has been fixed in version 2.4.1 of the Cockpit application. The fix includes implementing proper validation to prevent the upload of PHP files in the assets manager. Users are advised to upgrade to version 2.4.1 or later (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."