Product:

Openitcockpit

(It\-Novum)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 14
Date Id Summary Products Score Patch Annotated
2020-03-25 CVE-2020-10788 openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. Openitcockpit 9.1
2020-03-25 CVE-2020-10791 app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module. Openitcockpit N/A
2020-03-25 CVE-2020-10790 openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS. Openitcockpit N/A
2020-03-25 CVE-2020-10789 openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php. Openitcockpit N/A
2020-03-20 CVE-2020-10792 openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. Openitcockpit N/A
2019-12-31 CVE-2019-10227 openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. Openitcockpit N/A
2019-08-23 CVE-2019-15494 openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21. Openitcockpit 9.8
2019-08-23 CVE-2019-15493 openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. Openitcockpit 7.5
2019-08-23 CVE-2019-15492 openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. Openitcockpit 6.1
2019-08-23 CVE-2019-15491 openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. Openitcockpit 8.8