{"id":"UBUNTU-CVE-2020-35850","details":"** DISPUTED ** An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states \"I don't think [it] is a big real-life issue.\"","modified":"2020-12-30T02:15:00Z","published":"2020-12-30T02:15:00Z","withdrawn":"2025-06-23T15:53:49Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-35850"},{"type":"REPORT","url":"https://github.com/cockpit-project/cockpit/issues/15077"},{"type":"REPORT","url":"https://github.com/passtheticket/vulnerability-research/blob/main/cockpitProject/README.md"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-35850"}],"affected":[{"package":{"name":"cockpit","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/cockpit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["151-1","156-1","157-1","158-1","160-1","161-1","162-1","163-1","164-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35850.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/cockpit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["202.1-1","204-1","206-1","207-1","208-1","210-1","211-1","212-1","213-1","214.1-1","215-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35850.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/cockpit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["252-1","256-1","257-1","258-1","259-1","260-1","261-1","262-1","263-1","264-1","264-1ubuntu0.22.04.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35850.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/cockpit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["300.1-1","303-1","304-1","305-1","306-1","307-1","308-1","309-1","310.1-1","311-1","312-1build2","314-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-35850.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}