CVE-2018-10863
7.5HIGHIt was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An un
Published: 5/26/2021Updated: 11/21/2024
Description
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
AI AnalysisPowered by AI
Affected Products
redhatcertification
7.0
References
- https://access.redhat.com/security/cve/CVE-2018-10863Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1594122Issue TrackingVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-10863Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1594122Issue TrackingVendor Advisory