CRITICAL

CVE-2018-9302

CVSS v3

9.1

CRITICAL

EPSS Score

10.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

Technical details

Published
5/2/2018

Frequently asked questions

What is CVE-2018-9302?

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

Is CVE-2018-9302 actively exploited?

Active exploitation of CVE-2018-9302 has not been confirmed. The EPSS score is 10.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-9302?

CVE-2018-9302 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2018-9302 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.