CVE-2018-10867: Critical severity red hat certification vulnerability
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.
Other sources
Files are accessible without restrictions from the /update/results page of redhat-certification package, allowing an attacker to remove any file accessible by the apached user.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10867?
CVE-2018-10867 is a vulnerability that allows an attacker to remove any file accessible by the apached user on the /update/results page of redhat-certification 7 package.
What is the severity of CVE-2018-10867?
CVE-2018-10867 has a severity rating of 9.1 (Critical).
How can an attacker exploit CVE-2018-10867?
An attacker can exploit CVE-2018-10867 by accessing files without restrictions on the /update/results page of redhat-certification 7 package and removing any file accessible by the apached user.
Is there a fix available for CVE-2018-10867?
Yes, there is a fix available for CVE-2018-10867. Please refer to the official references for more information.
Where can I find more information about CVE-2018-10867?
You can find more information about CVE-2018-10867 in the official references provided.