<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T18:01:07.782831+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:2008</id>
    <title>ALSA-2022:2008 — Moderate: cockpit security, bug fix, and enhancement update</title>
    <updated>2026-10-10T18:01:07.787947+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: cockpit, AlmaLinux:8: cockpit-bridge, AlmaLinux:8: cockpit-doc, AlmaLinux:8: cockpit-system, AlmaLinux:8: cockpit-ws</p>
<p>Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.</p>
<p>The following packages have been upgraded to a later upstream version: cockpit (264.1). (BZ#1984902, BZ#1992620, BZ#2004041, BZ#2008208)</p>
<p>Security Fix(es):</p>
<p>* cockpit: authenticates with revoked certificates (CVE-2021-3698)</p>
<p>* cockpit: pages vulnerable to clickjacking (CVE-2021-3660)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:2008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20998</id>
    <title>EUVD-2026-20998</title>
    <updated>2026-10-10T18:01:07.788011+00:00</updated>
    <content>EUVD-2026-20998</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3698</id>
    <title>fkie_cve-2021-3698</title>
    <updated>2026-10-10T18:01:07.788028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w9ph-5m4x-c49r</id>
    <title>GHSA-w9ph-5m4x-c49r</title>
    <updated>2026-10-10T18:01:07.788052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w9ph-5m4x-c49r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3698</id>
    <title>gsd-2021-3698</title>
    <updated>2026-10-10T18:01:07.788069+00:00</updated>
    <content>gsd-2021-3698</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3698</id>
    <title>msrc_CVE-2021-3698 — A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by th…</title>
    <updated>2026-10-10T18:01:07.788080+00:00</updated>
    <content>msrc_CVE-2021-3698</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:2008</id>
    <title>RHSA-2022:2008 — Red Hat Security Advisory: cockpit security, bug fix, and enhancement update</title>
    <updated>2026-10-10T18:01:07.788097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cockpit: pages vulnerable to clickjacking cockpit: authenticates with revoked certificates</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:2008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3698</id>
    <title>UBUNTU-CVE-2021-3698</title>
    <updated>2026-10-10T18:01:07.788114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: cockpit</p>
<p>A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3698"/>
  </entry>
</feed>
