An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1ybWd4LTN3NHIteGNmcM4AA1Y0

High EPSS: 0.00287% (0.51654 Percentile) EPSS:

Cockpit Cross-site Scripting vulnerability

Affected Packages Affected Versions Fixed Versions
packagist:cockpit-hq/cockpit <= 2.6.3 No known fixed version
0 Dependent packages
0 Dependent repositories
76 Downloads total

Affected Version Ranges

All affected versions

2.0.0, 2.0.1, 2.0.2, 2.1.0, 2.1.1, 2.1.2, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit version 2.6.3 and prior. A patch is available at commit 2a93d391fbd2dd9e730f65d43b29beb65903d195 and anticipated to be part of version 2.6.4.

References: