VDB
Sign up
HIGH8.8

GHSA-j2rx-4jg9-79mw

Cockpit Vulnerable to Unrestricted Upload of File with Dangerous Type

Quick fix

GHSA-j2rx-4jg9-79mw — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.14.0

Details

Cockpit versions 2.13.5 and earlier are affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary files with the .php file extension enabling arbitrary code to be executed on the underlying server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.14.0
Fixcomposer require cockpit-hq/cockpit:^2.14.0

References