Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10869

Опубликовано: 18 июл. 2018
Источник: redhat
CVSS3: 7.5

Описание

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

It was discovered that redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

Меры по смягчению последствий

If SELinux is enabled it further restricts the set of files that can be downloaded through this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certification for Red Hat Enterprise Linux 6redhat-certificationNot affected
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certificationFixedRHSA-2018:237309.08.2018
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certification-hardwareFixedRHSA-2018:237309.08.2018
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certification-hardware-previewFixedRHSA-2018:237309.08.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1593780redhat-certification: /download allows to download any file

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

CVSS3: 7.5
github
больше 3 лет назад

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

7.5 High

CVSS3