4.3
CVSSv3

CVE-2021-3660

Published: 10/03/2022 Updated: 12/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cockpit-project cockpit

redhat enterprise linux 8.0

Vendor Advisories

No description is available for this CVE ...
Cockpit (and its plugins) do not seem to protect itself against clickjacking It is possible to render a page from a cockpit server via another website, inside an &lt;iFrame&gt; HTML entry This may be used by a malicious website in clickjacking or similar attacks ...