VDB
Sign up
HIGH8.8

GHSA-6x8f-x6qw-qwx3

cockpit-hq/cockpit is vulnerable to unrestricted file uploads

Quick fix

GHSA-6x8f-x6qw-qwx3 — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.4.1

Details

Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.4.1
Fixcomposer require cockpit-hq/cockpit:^2.4.1

References