Impact
The vulnerability causes the web worker restart script cron.php to disable TLS certificate verification. This allows an attacker on the outbound network path to the site to impersonate the target with any certificate, intercept the token used to start the web worker, and then launch the worker with that stolen token. The result is a confidentiality compromise that could allow unauthorized initiation of the web worker, potentially enabling further exploitation. The weakness is categorized as improper authentication via certificate validation, CWE‑295.
Affected Systems
Cockpit CMS by cockpit-hq, versions 2.12.0 through 2.14.0. The issue is fixed in version 2.14.1 and later.
Risk and Exploitability
The CVSS score is 2.3, indicating a low severity impact, and the EPSS score is unavailable. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need control of the network path to the site URL, making the attack vector intra‑network or man‑in‑the‑middle on outbound traffic. Given the low CVSS, the risk is primarily for systems that rely on the cron.php web worker and do not have additional protective controls such as TLS pinning or strict outbound filtering.
OpenCVE Enrichment