Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2022-03-07T13:59:18

Updated: 2024-08-03T17:01:08.335Z

Reserved: 2021-07-22T00:00:00

Link: CVE-2021-3660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-10T17:42:55.647

Modified: 2023-02-12T23:42:07.917

Link: CVE-2021-3660

cve-icon Redhat

Severity : Low

Publid Date: 2021-07-20T00:00:00Z

Links: CVE-2021-3660 - Bugzilla