Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Certification
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10866 1 Redhat 1 Certification 2021-06-04 6.4 MEDIUM 9.1 CRITICAL
It has been discovered that redhat-certification does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him. This flaw affects redhat-certification version 7.
CVE-2018-10867 1 Redhat 1 Certification 2021-06-04 6.4 MEDIUM 9.1 CRITICAL
It has been discovered that redhat-certification does not restrict file access in the /update/results page. A remote attacker could use this vulnerability to remove any file accessible by the user which is running httpd. This flaw affects redhat-certification version 7.
CVE-2018-10870 1 Redhat 2 Certification, Enterprise Linux 2019-10-09 7.5 HIGH 9.8 CRITICAL
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.