{"id":"CVE-2019-3804","details":"It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded cookie which could cause the web service to crash.","modified":"2026-08-07T11:48:21.256237768Z","published":"2019-03-26T18:29:00.543Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"4.0"},{"last_affected":"4.0"}],"source":"CPE_STRING","vendor_product":"redhat:virtualization","cpes":["cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1569"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1571"},{"type":"ADVISORY","url":"https://github.com/cockpit-project/cockpit/pull/10819"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3804"},{"type":"FIX","url":"https://github.com/cockpit-project/cockpit/commit/c51f6177576d7e12"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cockpit-project/cockpit","events":[{"introduced":"0"},{"fixed":"3128c62a9563246282a8d5129c7a42bb8397147a"},{"fixed":"c51f6177576d7e12"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"184"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:cockpit-project:cockpit:*:*:*:*:*:*:*:*"}}],"versions":["183","182","181","180","179","178","177","176","175","174","173","172","171","170","169","168","167","166","165","164","163","162","161","160","159","158","157","156","155","154","153","152","151","150","149","148","147","146","145","144","143","142","141","140","139","138","137","136","135","134","133","132","131","130","129","128","127","126","125","124","123","122","121","120","119","118","0.117","0.116","0.115","0.114","0.113","0.112","0.111","0.110","0.109","0.108","0.107","0.106","0.105","0.104","0.103","0.102","0.101","0.100","0.99","0.98","0.97","0.96-1","0.96","0.95","0.94","0.93","0.92","0.91","0.90","0.89","0.88","0.87","0.86","0.85","0.84","0.83","0.82","0.81","0.80","0.79","0.78","0.77","0.76","0.75","0.74","0.73","0.72","0.71","0.70","0.69","0.68","0.67","0.66","0.65","0.64","0.63","0.62","0.61","0.60","0.59","0.58","0.57","0.56","0.55","0.54","0.53","0.52","0.51","0.50","0.49","0.48","0.47","0.46","0.45","0.44","0.42","0.41","0.40","0.39","0.38","0.37","0.36","0.35","0.34","0.33","0.32","0.31","0.30","0.29","0.28","0.27","0.26","0.25","0.24","0.23","0.22","0.21","0.20","0.19","0.18","0.17","0.16","0.15","0.14","0.13","0.12","0.11","0.10","0.9","0.8","0.7","0.6","0.5","0.4","0.3","0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3804.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}