CVE-2018-10865
published 2021-05-26CVE-2018-10865: It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.03%
59.9th percentile
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certification | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rvw8-rq4h-hvg2: It has been discovered that redhat-certification does not perform an authorization check and allows an unauthenticated user to call a "restart" RPC me
ghsa_unreviewed·2022-05-24
CVE-2018-10865 [HIGH] CWE-862 GHSA-rvw8-rq4h-hvg2: It has been discovered that redhat-certification does not perform an authorization check and allows an unauthenticated user to call a "restart" RPC me
It has been discovered that redhat-certification does not perform an authorization check and allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system. An attacker could use this flaw to send requests to port 8009 of any host or to keep restarting the RHCertD daemon on a host of another customer. This flaw affects redhat-certification version 7.
Red Hat
redhat-certification: "restart" a node without authorization
vendor_redhat·2018-06-21·CVSS 7.5
CVE-2018-10865 [HIGH] CWE-862 redhat-certification: "restart" a node without authorization
redhat-certification: "restart" a node without authorization
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
It has been discovered that redhat-certification does not perform an authorization check and allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system. An attacker could use this flaw to send requests to port 8009 of any host or to keep restarting the RHCertD daemon on a host of another customer.
Package: redhat-certification (Red Hat Certification for Red Hat Enterprise Linux 6) - Not affected
Package: redhat-certification (Red Hat Certifi
No detection rules found.
No public exploits indexed.
2021-05-26
Published