Red Hat Bugzilla – Bug 1594122
CVE-2018-10863 redhat-certification: directory listing in /rhcert-transfer
Last modified: 2018-07-26 09:47:10 EDT
It has been discovered that redhat-certification is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
Acknowledgments: Name: Riccardo Schirone (Red Hat Product Security)