VDB
Sign up
MEDIUM6.5

GHSA-p46p-7pmj-m34f

Cockpit is vulnerable to directory traversal

Quick fix

GHSA-p46p-7pmj-m34f — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.14.0

Details

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.14.0
Fixcomposer require cockpit-hq/cockpit:^2.14.0

References