CVE-2026-105217: falha de baixa gravidade em cockpit-hq cockpit
Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php
Publicada em · Atualizada em
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 2.3epss 0.1%
probabilidade de exploração
0.1%top 99% das CVEs
exploração observada
nãonenhuma fonte reporta
Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
cockpit-hq · cockpitCVEs relacionadas — cockpit-hq cockpit
No mesmo produto, das mais perigosas para as menos.
Referências
https://github.com/Cockpit-HQ/Cockpithttps://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/cron.php#L70-L102https://github.com/Cockpit-HQ/Cockpit/commit/c611492adc17362578faa97f9c30b41e6c16e040https://github.com/Cockpit-HQ/Cockpit/issues/318https://www.vulncheck.com/advisories/cockpit-cms-2.12.0-before-2.14.1-disabled-tls-verification-via-cron-php