CVE-2018-10865

It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:certification:7.0:*:*:*:*:*:*:*

History

10 Feb 2023, 17:51

Type Values Removed Values Added
References (MISC) https://access.redhat.com/security/cve/CVE-2018-10865 - (MISC) https://access.redhat.com/security/cve/CVE-2018-10865 - Vendor Advisory

05 Aug 2022, 16:15

Type Values Removed Values Added
Summary It has been discovered that redhat-certification does not perform an authorization check and allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system. An attacker could use this flaw to send requests to port 8009 of any host or to keep restarting the RHCertD daemon on a host of another customer. This flaw affects redhat-certification version 7. It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2018-10865 -

04 Jun 2021, 15:46

Type Values Removed Values Added
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1593631 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1593631 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:redhat:certification:7.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

26 May 2021, 19:16

Type Values Removed Values Added
CWE CWE-862

26 May 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-26 19:15

Updated : 2023-12-10 13:55


NVD link : CVE-2018-10865

Mitre link : CVE-2018-10865

CVE.ORG link : CVE-2018-10865


JSON object : View

Products Affected

redhat

  • certification
CWE
CWE-862

Missing Authorization