Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxc4-ggqh-5wg4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

It has been discovered that redhat-certification does not restrict file access in the /update/results page. A remote attacker could use this vulnerability to remove any file accessible by the user which is running httpd. This flaw affects redhat-certification version 7.

It has been discovered that redhat-certification does not restrict file access in the /update/results page. A remote attacker could use this vulnerability to remove any file accessible by the user which is running httpd. This flaw affects redhat-certification version 7.

EPSS

Процентиль: 56%
0.00341
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 6.5
redhat
больше 7 лет назад

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.

CVSS3: 9.1
nvd
больше 4 лет назад

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.

EPSS

Процентиль: 56%
0.00341
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-552