Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10863

Опубликовано: 22 июн. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.

It has been discovered that redhat-certification is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certification for Red Hat Enterprise Linux 6redhat-certificationNot affected
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certificationAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=1594122redhat-certification: directory listing in /rhcert-transfer

EPSS

Процентиль: 46%
0.00235
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.

CVSS3: 7.5
github
больше 3 лет назад

It has been discovered that redhat-certification is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information. This flaw affects redhat-certification version 7.

EPSS

Процентиль: 46%
0.00235
Низкий

5.3 Medium

CVSS3