It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name.
Acknowledgments: Name: Riccardo Schirone (Red Hat Product Security)