CVE-2019-3804: Cockpit-Project Cockpit
High severity, CVSS 7.5. EPSS: 4.9% chance of exploitation in the next 30 days.
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.
Affected products
- Cockpit-Project Cockpit: before 184 (fixed in 184)
- Fedoraproject Fedora: affected versions not specified
- Red Hat Virtualization: version 4.0 only
Published 2019-03-26. Last modified 2026-06-17.