Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Do not remove SOS reports with strange names from the Cockpit web interface.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5655-1 | cockpit security update |
EUVD |
EUVD-2024-27889 | A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer. |
Thu, 26 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/o:redhat:enterprise_linux:10 |
Fri, 22 Nov 2024 12:00:00 +0000
Wed, 06 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T19:07:19.457Z
Reserved: 2024-03-26T16:48:38.370Z
Link: CVE-2024-2947
Updated: 2024-08-01T19:32:42.293Z
Status : Deferred
Published: 2024-03-28T19:15:48.693
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-2947
OpenCVE Enrichment
No data.
Debian DSA
EUVD