Vulnerability record · CVE-2020-35848 · published 30 December 2020
CVE-2020-35848: Agentejo Cockpit NoSQL injection in newpassword function
Agentejo · Cockpit
Cockpit before 0.11.2 is vulnerable to NoSQL injection through the Controller/Auth.php newpassword function. The flaw lets an unauthenticated remote attacker manipulate database queries, which matters because the endpoint is reachable over the network with no credentials or user interaction.
Description
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, a public exploit reference and very high EPSS probability make this an urgent patch target.
What it is
Cockpit before 0.11.2 is vulnerable to NoSQL injection through the Controller/Auth.php newpassword function. The flaw lets an unauthenticated remote attacker manipulate database queries, which matters because the endpoint is reachable over the network with no credentials or user interaction.
Impact
An attacker can read or alter data the application's database account can reach, and with the CVSS impact ratings of high confidentiality, integrity and availability, full compromise of the affected component is possible.
Attack surface
Reached over the network via the Cockpit newpassword authentication endpoint; the CVSS vector shows no privileges and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.74591 (99.5th percentile) and a public Packet Storm exploit reference exists, indicating active interest and available exploit code.
What to do
- Upgrade Cockpit to 0.11.2 or later, applying the vendor commits referenced in the advisory.
- If upgrade is not possible, restrict network access to the Cockpit authentication endpoints to trusted sources.
- Validate and type-check all input passed to the newpassword function so query operators cannot be injected.
- Run Cockpit with a database account limited to the minimum privileges needed.
- Monitor vendor advisories for further Cockpit authentication fixes.
Detection
- Review web logs for requests to the Cockpit newpassword endpoint containing NoSQL operators such as $ne, $gt or $where.
- Alert on authentication or password-reset requests from unexpected source IPs or with anomalous parameter structures.
- Audit database query logs for operator-style payloads originating from the Cockpit application.
- Check for unexpected changes to user records or credentials following suspicious newpassword requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/163762/Cockpit-CMS-0.11.1-NoSQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://getcockpit.com/ | ProductVendor Advisory |
| https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466 | PatchVendor Advisory |
| https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af | PatchVendor Advisory |
| https://github.com/agentejo/cockpit/commit/79fc9631ffa29146e3124ceaf99879b92e1ef24b | PatchVendor Advisory |
| http://packetstormsecurity.com/files/163762/Cockpit-CMS-0.11.1-NoSQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://getcockpit.com/ | ProductVendor Advisory |
| https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466 | PatchVendor Advisory |
| https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af | PatchVendor Advisory |
| https://github.com/agentejo/cockpit/commit/79fc9631ffa29146e3124ceaf99879b92e1ef24b | PatchVendor Advisory |
Track CVE-2020-35848 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35848), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.