Security Advisory

CVE-2025-1025

7.5
HIGH

Vulnerability Description

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
Published Date February 5, 2025
Official Source NIST NVD Advisory