CVE-2025-1025
Severity CVSS v4.0:
HIGH
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
05/02/2025
Last modified:
05/02/2025
Description
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://gist.github.com/CHOOCS/fe1227443544d5d74c33982814f290af
- https://github.com/Cockpit-HQ/Cockpit/commit/984ef9ad270357b843af63c81db95178eae42cae
- https://github.com/Cockpit-HQ/Cockpit/commit/becca806c7071ecc732521bb5ad0bb9c64299592
- https://security.snyk.io/vuln/SNYK-PHP-COCKPITHQCOCKPIT-8516320
- https://gist.github.com/CHOOCS/fe1227443544d5d74c33982814f290af



