Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
Recent assessments:
h00die at May 31, 2021 12:07pm UTC reported:
noSQL injection within the /auth/requestreset
API. By sending JSON.generate({ 'user' => { '$func' => 'var_dump' } })
it causes the var_dump
function to be called, which dumps all memory for the user
object. This, in effect, allows for enumerating all usernames on the system. This can be combined with CVE-2020-35847 to eventually get an RCE.
Assessed Attacker Value: 4
Assessed Attacker Value: 4Assessed Attacker Value: 5
packetstormsecurity.com/files/162282/Cockpit-CMS-0.11.1-NoSQL-Injection-Remote-Command-Execution.html
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35846
getcockpit.com/
github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466
github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af
github.com/agentejo/cockpit/commit/79fc9631ffa29146e3124ceaf99879b92e1ef24b