PT-2021-8692 · Red Hat · Redhat-Certification
Riccardo Schirone
·
Published
2021-05-26
·
Updated
2023-02-10
·
CVE-2018-10866
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
redhat-certification version 7
Description
The issue concerns the /configuration view of redhat-certification, which fails to perform an authorization check. This allows an unauthenticated user to remove a system file, specifically an XML file containing host-related information that does not belong to them.
Recommendations
For redhat-certification version 7, consider restricting access to the /configuration view to prevent unauthorized removal of system files until a proper authorization check is implemented. As a temporary workaround, restrict access to the system XML files to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redhat-Certification