redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105061 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10869 | issue tracking vendor advisory mitigation |
https://access.redhat.com/errata/RHSA-2018:2373 | vendor advisory |