Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Openitcockpit
(It\-Novum)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 14 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-06-13 | CVE-2023-3218 | Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. | Openitcockpit | 4.4 | ||
2023-06-25 | CVE-2023-36663 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | Openitcockpit | 8.8 | ||
2023-07-06 | CVE-2023-3520 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | Openitcockpit | 4.6 | ||
2019-08-23 | CVE-2019-15490 | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. | Openitcockpit | 9.8 | ||
2020-03-25 | CVE-2020-10788 | openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. | Openitcockpit | 9.1 | ||
2020-03-25 | CVE-2020-10791 | app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module. | Openitcockpit | N/A | ||
2020-03-25 | CVE-2020-10790 | openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. | Openitcockpit | N/A | ||
2020-03-25 | CVE-2020-10789 | openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php. | Openitcockpit | N/A | ||
2020-03-20 | CVE-2020-10792 | openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. | Openitcockpit | N/A | ||
2019-12-31 | CVE-2019-10227 | openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | Openitcockpit | N/A |