Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10866

Опубликовано: 21 июн. 2018
Источник: redhat
CVSS3: 5.3

Описание

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certification for Red Hat Enterprise Linux 6redhat-certificationNot affected
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certificationAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1593632redhat-certification: remove a "system" file without authorization

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
больше 4 лет назад

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.

CVSS3: 9.1
github
больше 3 лет назад

It has been discovered that redhat-certification does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him. This flaw affects redhat-certification version 7.

5.3 Medium

CVSS3