CVE-2019-3804

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-3804
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3804.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-3804
Downstream
Published
2019-03-26T18:29:00.543Z
Modified
2025-11-20T11:04:32.012917Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.

References

Affected packages

Git / github.com/cockpit-project/cockpit

Affected ranges

Type
GIT
Repo
https://github.com/cockpit-project/cockpit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.10
0.100
0.101
0.102
0.103
0.104
0.105
0.106
0.107
0.108
0.109
0.11
0.110
0.111
0.112
0.113
0.114
0.115
0.116
0.117
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.2
0.20
0.21
0.22
0.23
0.24
0.25
0.26
0.27
0.28
0.29
0.3
0.30
0.31
0.32
0.33
0.34
0.35
0.36
0.37
0.38
0.39
0.4
0.40
0.41
0.42
0.44
0.45
0.46
0.47
0.48
0.49
0.5
0.50
0.51
0.52
0.53
0.54
0.55
0.56
0.57
0.58
0.59
0.6
0.60
0.61
0.62
0.63
0.64
0.65
0.66
0.67
0.68
0.69
0.7
0.70
0.71
0.72
0.73
0.74
0.75
0.76
0.77
0.78
0.79
0.8
0.80
0.81
0.82
0.83
0.84
0.85
0.86
0.87
0.88
0.89
0.9
0.90
0.91
0.92
0.93
0.94
0.95
0.96
0.96-1
0.97
0.98
0.99

Other

118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183