<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:34:27 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:3667 — Moderate: cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:3667</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cockpit, AlmaLinux:8: cockpit-bridge, AlmaLinux:8: cockpit-doc, AlmaLinux:8: cockpit-system, AlmaLinux:8: cockpit-ws&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: command injection when deleting a sosreport with a crafted name (CVE-2024-2947)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cockpit, AlmaLinux:8: cockpit-bridge, AlmaLinux:8: cockpit-doc, AlmaLinux:8: cockpit-system, AlmaLinux:8: cockpit-ws&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: command injection when deleting a sosreport with a crafted name (CVE-2024-2947)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:3667</guid>
    </item>
    <item>
      <title>bdu:2024-02724</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02724</link>
      <description>bdu:2024-02724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02724</guid>
    </item>
    <item>
      <title>EUVD-2026-261540</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261540</link>
      <description>EUVD-2026-261540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261540</guid>
    </item>
    <item>
      <title>fkie_cve-2024-2947</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-2947</link>
      <description>&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-2947</guid>
    </item>
    <item>
      <title>GHSA-8rqc-wx6q-m4qc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8rqc-wx6q-m4qc</link>
      <description>&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8rqc-wx6q-m4qc</guid>
    </item>
    <item>
      <title>gsd-2024-2947</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-2947</link>
      <description>gsd-2024-2947</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-2947</guid>
    </item>
    <item>
      <title>OESA-2026-2907 — cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit makes GNU/Linux discoverable. See Linux server in a web browser and perform system tasks with a mouse. It’s easy to start containers, administer storage, configure networks, and inspect logs with this package.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.(CVE-2024-2947)&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.(CVE-2026-4802)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2907</guid>
    </item>
    <item>
      <title>RHSA-2024:3667 — Red Hat Security Advisory: cockpit security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3667</link>
      <description>&lt;p&gt;cockpit: command injection when deleting a sosreport with a crafted name&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cockpit: command injection when deleting a sosreport with a crafted name&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3667</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-2947</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-2947</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.10: cockpit&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.10: cockpit&lt;/p&gt;
&lt;p&gt;A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-2947</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1305 — Red Hat Enterprise Linux (cockpit): Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1305</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1305</guid>
    </item>
  </channel>
</rss>
