<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:34:14.816246+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:3667</id>
    <title>ALSA-2024:3667 — Moderate: cockpit security update</title>
    <updated>2026-10-02T22:34:14.959648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: cockpit, AlmaLinux:8: cockpit-bridge, AlmaLinux:8: cockpit-doc, AlmaLinux:8: cockpit-system, AlmaLinux:8: cockpit-ws</p>
<p>Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.</p>
<p>Security Fix(es):</p>
<p>* cockpit: command injection when deleting a sosreport with a crafted name (CVE-2024-2947)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:3667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02724</id>
    <title>bdu:2024-02724</title>
    <updated>2026-10-02T22:34:14.959757+00:00</updated>
    <content>bdu:2024-02724</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261540</id>
    <title>EUVD-2026-261540</title>
    <updated>2026-10-02T22:34:14.959791+00:00</updated>
    <content>EUVD-2026-261540</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-2947</id>
    <title>fkie_cve-2024-2947</title>
    <updated>2026-10-02T22:34:14.959815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-2947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8rqc-wx6q-m4qc</id>
    <title>GHSA-8rqc-wx6q-m4qc</title>
    <updated>2026-10-02T22:34:14.959851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8rqc-wx6q-m4qc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-2947</id>
    <title>gsd-2024-2947</title>
    <updated>2026-10-02T22:34:14.959878+00:00</updated>
    <content>gsd-2024-2947</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-2947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2907</id>
    <title>OESA-2026-2907 — cockpit security update</title>
    <updated>2026-10-02T22:34:14.959896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: cockpit</p>
<p>Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.

Security Fix(es):</p>
<p>A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)</p>
<p>A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3667</id>
    <title>RHSA-2024:3667 — Red Hat Security Advisory: cockpit security update</title>
    <updated>2026-10-02T22:34:14.959956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cockpit: command injection when deleting a sosreport with a crafted name</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-2947</id>
    <title>Withdrawn: UBUNTU-CVE-2024-2947</title>
    <updated>2026-10-02T22:34:14.959986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:24.10: cockpit</p>
<p>A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-2947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1305</id>
    <title>WID-SEC-W-2024-1305 — Red Hat Enterprise Linux (cockpit): Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T22:34:14.960019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1305"/>
  </entry>
</feed>
