Red Hat Bugzilla – Bug 1593764
CVE-2018-10867 redhat-certification: /uploads/results page allows to remove files
Last modified: 2018-07-26 05:58:56 EDT
Files are accessible without restrictions from the /update/results page of redhat-certification package, allowing an attacker to remove any file accessible by the apached user.
Acknowledgments: Name: Riccardo Schirone (Red Hat Product Security)
Mitigation: If SELinux is enabled, it will restrict the number of files accessible by the httpd process.
The uploadResults view does not properly check the resultsPath, allowing any user to download existing files.