First published: Fri Jun 22 2018(Updated: )
It has been discovered that redhat-certification is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Certification | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10863 is high.
CVE-2018-10863 affects Redhat Certification 7 by allowing an unauthorized attacker to gather sensitive information.
An attacker can exploit CVE-2018-10863 by accessing the /rhcert-transfer URL to list all files and directories in the /var/www/rhcert/store/transfer directory.
Yes, there are fixes available for CVE-2018-10863. It is recommended to update the redhat-certification software to a patched version.
More information about CVE-2018-10863 can be found on the Red Hat Bugzilla and Red Hat Security Advisory websites.