It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1593631 | issue tracking vendor advisory |
https://access.redhat.com/security/cve/CVE-2018-10865 | vendor advisory |