7.5
CVSSv3

CVE-2019-3804

Published: 26/03/2019 Updated: 07/11/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cockpit-project cockpit

fedoraproject fedora -

redhat virtualization 4.0

Vendor Advisories

Synopsis Moderate: redhat-virtualization-host security and enhancement update Type/Severity Security Advisory: Moderate Topic An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a secur ...
Synopsis Moderate: cockpit security update Type/Severity Security Advisory: Moderate Topic An update for cockpit is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Moderate: rhvm-appliance security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of ...
Impact: Moderate Public Date: 2018-12-13 CWE: CWE-119 Bugzilla: 1663567: CVE-2019-3804 cockpit: Crash w ...