PT-2021-8691 · Red Hat · Redhat-Certification

·

CVE-2018-10865

·

Published

2021-05-26

·

Updated

2023-02-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions redhat-certification version 7
Description The issue concerns the /configuration view, which lacks an authorization check. This allows an unauthenticated user to invoke a restart RPC method on any accessible host, regardless of ownership.
Recommendations For redhat-certification version 7, consider restricting access to the /configuration view until a proper authorization check is implemented to prevent unauthorized RPC method calls. As a temporary workaround, restrict access to the restart RPC method to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10865

Affected Products

Redhat-Certification