Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v46-5c9p-j4mg

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

EPSS

Процентиль: 67%
0.00531
Низкий

7.5 High

CVSS3

Дефекты

CWE-552
CWE-732

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

CVSS3: 7.5
nvd
больше 7 лет назад

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

EPSS

Процентиль: 67%
0.00531
Низкий

7.5 High

CVSS3

Дефекты

CWE-552
CWE-732