PT-2021-8692 · Red Hat · Redhat-Certification

Riccardo Schirone

·

Published

2021-05-26

·

Updated

2023-02-10

·

CVE-2018-10866

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions redhat-certification version 7
Description The issue concerns the /configuration view of redhat-certification, which fails to perform an authorization check. This allows an unauthenticated user to remove a system file, specifically an XML file containing host-related information that does not belong to them.
Recommendations For redhat-certification version 7, consider restricting access to the /configuration view to prevent unauthorized removal of system files until a proper authorization check is implemented. As a temporary workaround, restrict access to the system XML files to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2018-10866

Affected Products

Redhat-Certification