{"id":"CVE-2020-10792","details":"openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing \"dev\" or \"staging\" in the HTTP Host header.","modified":"2026-08-27T08:15:07.025492Z","published":"2020-03-20T18:15:13.997Z","references":[{"type":"ADVISORY","url":"https://openitcockpit.io/2020/2020/03/23/openitcockpit-3-7-3-released/"},{"type":"FIX","url":"https://github.com/it-novum/openITCOCKPIT/commit/719410b9ffff7d7b29dba7aad58faceb5eff789f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openITCOCKPIT/openITCOCKPIT","events":[{"introduced":"0"},{"last_affected":"e273e9881289cc086aa3bddb56e8d17a3180286b"}],"database_specific":{"cpe":"cpe:2.3:a:it-novum:openitcockpit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.7.2"}],"source":"CPE_RANGE"}}],"versions":["openITCOCKPIT-3.7.2","openITCOCKPIT-3.6.1-2","openITCOCKPIT-3.6.1","openITCOCKPIT-3.5.0","openITCOCKPIT-3.3.0-3","openITCOCKPIT-3.2.0","openITCOCKPIT-3.1.1","openITCOCKPIT-3.1.0","openITCOCKPIT-3.0.10-16","openITCOCKPIT-3.0.10-15","openITCOCKPIT-3.0.10-14","openITCOCKPIT-3.0.10-13","openITCOCKPIT-3.0.10-12","openITCOCKPIT-3.0.10-8","openITCOCKPIT-3.0.10-4","openITCOCKPIT-3.0.7","openITCOCKPIT-3.0.6-1","openITCOCKPIT-3.0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-10792.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/openitcockpit/openitcockpit","events":[{"introduced":"0"},{"fixed":"719410b9ffff7d7b29dba7aad58faceb5eff789f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["openITCOCKPIT-3.7.2","openITCOCKPIT-3.6.1-2","openITCOCKPIT-3.6.1","openITCOCKPIT-3.5.0","openITCOCKPIT-3.3.0-3","openITCOCKPIT-3.2.0","openITCOCKPIT-3.1.1","openITCOCKPIT-3.1.0","openITCOCKPIT-3.0.10-16","openITCOCKPIT-3.0.10-15","openITCOCKPIT-3.0.10-14","openITCOCKPIT-3.0.10-13","openITCOCKPIT-3.0.10-12","openITCOCKPIT-3.0.10-8","openITCOCKPIT-3.0.10-4","openITCOCKPIT-3.0.7","openITCOCKPIT-3.0.6-1","openITCOCKPIT-3.0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-10792.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}