CVE-2021-3660 describes a clickjacking vulnerability in Cockpit and its plugins, affecting products such as cockpit_project cockpit and Red Hat Enterprise Linux. This medium-severity vulnerability (CVSS 4.3) allows an attacker to embed a Cockpit page within an iframe on a malicious website, potentially tricking users into unintended actions. While the attack complexity is low, the impact is limited to integrity, with no confidentiality or availability concerns. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 254CPE matchmatch criteria | cpe:2.3:a:cockpit-project:cockpit:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
Mar 8, 2022cockpit: pages vulnerable to clickjacking
Jul 20, 2021