PT-2021-9110 · Red Hat · Redhat-Certification
Published
2021-03-16
·
Updated
2021-03-22
·
CVE-2019-3897
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Certification versions 6 and 7
Description
It has been discovered that any unauthorized user may download any file under /var/www/rhcert, provided they know its name.
Recommendations
For Red Hat Certification version 6, restrict access to the /var/www/rhcert directory to prevent unauthorized file downloads.
For Red Hat Certification version 7, restrict access to the /var/www/rhcert directory to prevent unauthorized file downloads.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redhat-Certification