CVE-2024-2947: Red Hat Enterprise Linux 10
High severity, CVSS 7.3. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 0:310.4-1.el8_10 (fixed in 0:310.4-1.el8_10)
- Red Hat Red Hat Enterprise Linux 9: before 0:311.2-1.el9_4 (fixed in 0:311.2-1.el9_4)
Published 2024-03-28. Last modified 2026-06-17.