VDB
Sign up
HIGH7.5

GHSA-wp68-xrfg-xvq4

Cockpit Arbitrary File Upload

Quick fix

GHSA-wp68-xrfg-xvq4 — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.4.1

Details

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.4.1
Fixcomposer require cockpit-hq/cockpit:^2.4.1

References