MEDIUM6.5
GHSA-p46p-7pmj-m34f
Cockpit is vulnerable to directory traversal
Quick fix
GHSA-p46p-7pmj-m34f — cockpit-hq/cockpit: upgrade to the fixed version with the command below.
composer require cockpit-hq/cockpit:^2.14.0Details
Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cockpit-hq/cockpit
Introduced in:
0Fixed in: 2.14.0Fix
composer require cockpit-hq/cockpit:^2.14.0