Back

CRITICAL

redhat-certification: /uploads/results page allows to remove files

Published May 26, 2021

Description

Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an attacker to remove any file accessible by the apached user.

Affected products

Remediation

Red Hat mitigation

If SELinux is enabled, it will restrict the number of files accessible by the httpd process.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 26, 2021
Updated Aug 5, 2024
Reserved May 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 21, 2018