CVE-2018-10863: High severity red hat certification vulnerability
It has been discovered that redhat-certification is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
Other sources
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10863?
The severity of CVE-2018-10863 is high.
How does CVE-2018-10863 affect Redhat Certification 7?
CVE-2018-10863 affects Redhat Certification 7 by allowing an unauthorized attacker to gather sensitive information.
How can an attacker exploit CVE-2018-10863?
An attacker can exploit CVE-2018-10863 by accessing the /rhcert-transfer URL to list all files and directories in the /var/www/rhcert/store/transfer directory.
Are there any known fixes for CVE-2018-10863?
Yes, there are fixes available for CVE-2018-10863. It is recommended to update the redhat-certification software to a patched version.
Where can I find more information about CVE-2018-10863?
More information about CVE-2018-10863 can be found on the Red Hat Bugzilla and Red Hat Security Advisory websites.