ZeroHour

CVE-2019-3804

CVSS 3.1
7.5 high
EPSS
5%p91
Published
()
Modified
Description

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

Vendors
cockpit-projectfedoraprojectredhat
Products
cockpit, fedora, virtualization
Weakness
CWE-909
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.