← Πίσω στην αναζήτηση CVE

CVE-2026-44985

Dozzle

Περιγραφή

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH). An attacker hosting a page on a same-site origin (e.g., a sibling subdomain, or another service on localhost) can initiate a WebSocket connection to the exec endpoint that carries the victim-s valid JWT cookie, gaining interactive shell access in any container the victim is authorized to access. This vulnerability is fixed in 10.5.2.

CVSS 9.6EPSS 0.19499999999999998%Κίνδυνος 0.98
Προβολή πηγής
Δημοσίευση
2026-05-26 22:16:43
Επηρεαζόμενες εκδόσεις
<10.5.2
Τύπος
Core software
Τελευταία τροποποίηση
2026-07-24 12:10:00
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H