Back

HIGH

redhat-certification: /download allows to download any file

Published Jul 19, 2018

Description

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

Affected products

Remediation

Red Hat mitigation

If SELinux is enabled it further restricts the set of files that can be downloaded through this flaw.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 19, 2018
Updated Aug 5, 2024
Reserved May 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 18, 2018