Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
{ "vanir_signatures": [ { "source": "https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10", "deprecated": false, "target": { "file": "src/common/cockpitwebresponse.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "134655402416378279483429680485234518541", "292222678174790241311677260487533223928", "309271648936713598462387289853482135675", "268971167726584180281546125277119645421", "133267846151928897689910292218534056527", "3397344417416461134128263470272402462", "281014394522471031140424059057317025718", "144330048431258142360128838096477822215", "173555419823742892274023789639976169352", "56982047601249035356228339888196003252", "86012658027789560600591753589253616155", "130140710033837481933422337657713424558" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2021-3660-0b2bf10d" }, { "source": "https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10", "deprecated": false, "target": { "file": "src/common/cockpitwebresponse.c", "function": "finish_headers" }, "signature_version": "v1", "digest": { "length": 1908.0, "function_hash": "218541981637196949492337221263490501649" }, "signature_type": "Function", "id": "CVE-2021-3660-88da9a07" }, { "source": "https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10", "deprecated": false, "target": { "file": "src/common/cockpitwebresponse.c", "function": "append_header" }, "signature_version": "v1", "digest": { "length": 1155.0, "function_hash": "64335642523941509145852724743639902650" }, "signature_type": "Function", "id": "CVE-2021-3660-d186b283" } ] }