PT-2021-8692 · Red Hat · Redhat-Certification

·

CVE-2018-10866

·

Published

2021-05-26

·

Updated

2023-02-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions redhat-certification version 7
Description The issue concerns the /configuration view of redhat-certification, which fails to perform an authorization check. This allows an unauthenticated user to remove a system file, specifically an XML file containing host-related information that does not belong to them.
Recommendations For redhat-certification version 7, consider restricting access to the /configuration view to prevent unauthorized removal of system files until a proper authorization check is implemented. As a temporary workaround, restrict access to the system XML files to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10866

Affected Products

Redhat-Certification