Related Vulnerabilities: CVE-2021-3660  

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

Severity Medium

Remote Yes

Type Insufficient validation

Description

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

AVG-1393 cockpit 249-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1980688
https://github.com/cockpit-project/cockpit/issues/16122
https://cockpit-project.org/guide/latest/embedding.html