Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2022-03-07T13:59:18

Updated: 2022-03-07T13:59:18

Reserved: 2021-07-22T00:00:00


Link: CVE-2021-3660

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-03-10T17:42:55.647

Modified: 2023-02-12T23:42:07.917


Link: CVE-2021-3660

JSON object: View

cve-icon Redhat Information

No data.

CWE