PT-2021-8691 · Red Hat · Redhat-Certification

Riccardo Schirone

·

Published

2021-05-26

·

Updated

2023-02-10

·

CVE-2018-10865

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions redhat-certification version 7
Description The issue concerns the /configuration view, which lacks an authorization check. This allows an unauthenticated user to invoke a restart RPC method on any accessible host, regardless of ownership.
Recommendations For redhat-certification version 7, consider restricting access to the /configuration view until a proper authorization check is implemented to prevent unauthorized RPC method calls. As a temporary workaround, restrict access to the restart RPC method to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2018-10865

Affected Products

Redhat-Certification