Vulnerabilities > Redhat > Certification > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-05-26 CVE-2018-10867 Files or Directories Accessible to External Parties vulnerability in Redhat Certification 7.0
Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.
network
low complexity
redhat CWE-552
critical
9.1
2021-05-26 CVE-2018-10866 Missing Authorization vulnerability in Redhat Certification 7.0
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.
network
low complexity
redhat CWE-862
critical
9.1
2018-07-19 CVE-2018-10870 Improper Input Validation vulnerability in Redhat Certification
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile.
network
low complexity
redhat CWE-20
critical
9.8