-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing X-Frame-Options headers in HTTP responses. The patch adds this header in the 'after' event handler in modules/App/admin.php. The anonymous function handling this event in vulnerable versions failed to implement frame restrictions, making UI layers susceptible to embedding via iframes. This matches CWE-1021's description of improper UI layer restriction.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| cockpit-hq/cockpit | composer | < 2.3.9 | 2.3.9 |
Ongoing coverage of React2Shell