Red Hat Security Advisory: cockpit security update
A command injection vulnerability (CVE-2024-2947) exists in the Cockpit web-based server administration tool used in Red Hat Enterprise Linux 9. The issue occurs when deleting a sosreport with a crafted name, allowing potential command injection. Red Hat has released a security update to address this vulnerability. The severity is rated as moderate by Red Hat Product Security.
AI Analysis
Technical Summary
CVE-2024-2947 is a command injection vulnerability in the Cockpit tool for administering GNU/Linux servers via a web browser. Specifically, the flaw arises when deleting a sosreport that has a specially crafted name, which can lead to command injection (CWE-77). This vulnerability affects Red Hat Enterprise Linux 9 across multiple architectures and variants. Red Hat has issued a security advisory (RHSA-2024:3843) and released updated packages to fix this issue.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected system with the privileges of the Cockpit service. This could lead to unauthorized system control or disruption. The vulnerability is rated as moderate in severity by Red Hat, indicating a significant but not critical risk.
Mitigation Recommendations
Red Hat has released an official security update for Cockpit in Red Hat Enterprise Linux 9 to fix this command injection vulnerability. Users should apply the update as described in the Red Hat advisory RHSA-2024:3843 and the referenced article https://access.redhat.com/articles/11258. No alternative mitigations are specified, so applying the official patch is the recommended action.
Red Hat Security Advisory: cockpit security update
Description
A command injection vulnerability (CVE-2024-2947) exists in the Cockpit web-based server administration tool used in Red Hat Enterprise Linux 9. The issue occurs when deleting a sosreport with a crafted name, allowing potential command injection. Red Hat has released a security update to address this vulnerability. The severity is rated as moderate by Red Hat Product Security.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-2947 is a command injection vulnerability in the Cockpit tool for administering GNU/Linux servers via a web browser. Specifically, the flaw arises when deleting a sosreport that has a specially crafted name, which can lead to command injection (CWE-77). This vulnerability affects Red Hat Enterprise Linux 9 across multiple architectures and variants. Red Hat has issued a security advisory (RHSA-2024:3843) and released updated packages to fix this issue.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected system with the privileges of the Cockpit service. This could lead to unauthorized system control or disruption. The vulnerability is rated as moderate in severity by Red Hat, indicating a significant but not critical risk.
Mitigation Recommendations
Red Hat has released an official security update for Cockpit in Red Hat Enterprise Linux 9 to fix this command injection vulnerability. Users should apply the update as described in the Red Hat advisory RHSA-2024:3843 and the referenced article https://access.redhat.com/articles/11258. No alternative mitigations are specified, so applying the official patch is the recommended action.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:3843
- Cve Count
- 1
Threat ID: 6a1f4ea2e29bf47b500889ac
Added to database: 06/02/2026, 21:44:02 UTC
Last enriched: 06/26/2026, 02:15:41 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.