Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10865

Опубликовано: 26 мая 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:certification:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00977
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 5.8
redhat
больше 7 лет назад

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.

CVSS3: 7.5
github
больше 3 лет назад

It has been discovered that redhat-certification does not perform an authorization check and allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system. An attacker could use this flaw to send requests to port 8009 of any host or to keep restarting the RHCertD daemon on a host of another customer. This flaw affects redhat-certification version 7.

EPSS

Процентиль: 76%
0.00977
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-862
CWE-862