CVE-2019-3804

Related Vulnerabilities: CVE-2019-3804  

Impact: Moderate Public Date: 2018-12-13 CWE: CWE-119 Bugzilla: 1663567: CVE-2019-3804 cockpit: Crash when parsing invalid base64 headers It was found that cockpit used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

It was found that cockpit used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

Find out more about CVE-2019-3804 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Virtualization 4 rhvm-appliance Affected
Red Hat Virtualization 4 redhat-virtualization-host Affected
Red Hat OpenShift Enterprise 3.2 cockpit Under investigation
Red Hat OpenShift Container Platform 3.9 cockpit Under investigation
Red Hat OpenShift Container Platform 3.7 cockpit Under investigation
Red Hat OpenShift Container Platform 3.6 cockpit Under investigation
Red Hat OpenShift Container Platform 3.5 cockpit Under investigation
Red Hat OpenShift Container Platform 3.4 cockpit Under investigation
Red Hat OpenShift Container Platform 3.3 cockpit Under investigation
Red Hat OpenShift Container Platform 3.11 cockpit Under investigation
Red Hat OpenShift Container Platform 3.10 cockpit Under investigation
Red Hat Enterprise Linux 7 cockpit Affected

External References