Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
CVSS Information
N/A
Vulnerability Type
证书验证不恰当
Vulnerability Title
Cockpit 信任管理问题漏洞
Vulnerability Description
Cockpit是一个交互式服务器管理界面。 Cockpit 中存在安全漏洞,该漏洞允许客户端证书成功地进行身份验证,而不管证书吊销列表(CRL)配置或证书状态如何。
CVSS Information
N/A
Vulnerability Type
N/A