PT-2021-8691 · Red Hat · Redhat-Certification
Riccardo Schirone
·
Published
2021-05-26
·
Updated
2023-02-10
·
CVE-2018-10865
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
redhat-certification version 7
Description
The issue concerns the /configuration view, which lacks an authorization check. This allows an unauthenticated user to invoke a restart RPC method on any accessible host, regardless of ownership.
Recommendations
For redhat-certification version 7, consider restricting access to the /configuration view until a proper authorization check is implemented to prevent unauthorized RPC method calls. As a temporary workaround, restrict access to the restart RPC method to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redhat-Certification