CVE-2018-9302: Getcockpit Cockpit

Critical severity, CVSS 9.1. EPSS: 8.5% chance of exploitation in the next 30 days.

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

Affected products

  • Getcockpit Cockpit: from 0.4.4, up to and including 0.5.5

Published 2018-05-02. Last modified 2026-06-17.