Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 38: 2024-31e83b461d moderate: Fix Cockpit Command Injection

fedora
Calendar Grey April 18, 2024
Dist Fedora Esm H88
Mitigating command injection vulnerability in Fedora 38's cockpit through specially designed report identifiers, crucial security enhancement.
sosreport: Fix command injection with crafted report names [CVE-2024-2947]

Summary

The Cockpit Web Console enables users to administer GNU/Linux servers using a

web browser.

It offers network configuration, log inspection, diagnostic reports, SELinux

troubleshooting, interactive command-line sessions, and more.

Update Information:

sosreport: Fix command injection with crafted report names [CVE-2024-2947]

Change Log

* Tue Apr 2 2024 Packit - 311.2-1 - sosreport: Fix command injection with crafted report names [CVE-2024-2947]

References


[ 1 ] Bug #2271815 - CVE-2024-2947 cockpit: command injection when deleting a sosreport with a crafted name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271815

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-31e83b461d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: cockpit
Product: Fedora 38
Version: 311.2
Release: 1.fc38
Summary: Web Console for Linux servers

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here