Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
[
{
"id": "CVE-2021-3660-0b2bf10d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"134655402416378279483429680485234518541",
"292222678174790241311677260487533223928",
"309271648936713598462387289853482135675",
"268971167726584180281546125277119645421",
"133267846151928897689910292218534056527",
"3397344417416461134128263470272402462",
"281014394522471031140424059057317025718",
"144330048431258142360128838096477822215",
"173555419823742892274023789639976169352",
"56982047601249035356228339888196003252",
"86012658027789560600591753589253616155",
"130140710033837481933422337657713424558"
],
"threshold": 0.9
},
"target": {
"file": "src/common/cockpitwebresponse.c"
},
"source": "https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10"
},
{
"id": "CVE-2021-3660-88da9a07",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "218541981637196949492337221263490501649",
"length": 1908.0
},
"target": {
"file": "src/common/cockpitwebresponse.c",
"function": "finish_headers"
},
"source": "https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10"
},
{
"id": "CVE-2021-3660-d186b283",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "64335642523941509145852724743639902650",
"length": 1155.0
},
"target": {
"file": "src/common/cockpitwebresponse.c",
"function": "append_header"
},
"source": "https://github.com/cockpit-project/cockpit/commit/8d9bc10d8128aae03dfde62fd00075fe492ead10"
}
]