
Cloud Vulnerability DB
A community-led vulnerabilities database
A command injection vulnerability (CVE-2024-2947) was discovered in Cockpit, affecting versions 270 and newer. The vulnerability was identified in the web interface's sosreport deletion functionality, where a crafted report name could be used to execute arbitrary commands (NVD, Red Hat CVE).
The vulnerability exists in Cockpit's diagnostic reports module where the deletion of sosreport files with specially crafted names could lead to command injection. The issue has a CVSS v3.1 base score of 7.3 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command) (NVD).
If exploited, this vulnerability could result in privilege escalation through command injection, potentially allowing an attacker to execute arbitrary commands with elevated privileges on the affected system (Red Hat CVE).
The vulnerability requires local access and user interaction through the Cockpit web interface. An attacker would need to craft a specific sosreport name and trick a user into deleting it through the web interface to trigger the command injection (Red Hat Bugzilla).
The vulnerability has been fixed in Cockpit version 314. Red Hat has released security updates for affected versions through RHSA-2024:3667 for RHEL 8 and RHSA-2024:3843 for RHEL 9. Fedora has also released updates for versions 38, 39, and 40 (Red Hat Advisory, Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."