CVE-2018-10865 Details
Description
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
An authorization bypass vulnerability has been identified in Red Hat Certification for Red Hat Enterprise Linux 7. The issue allows unauthenticated users to invoke a 'restart' RPC method on any host accessible by the system, regardless of ownership. This vulnerability arises because the '/configuration' view does not implement proper authorization checks. As a result, an attacker could potentially disrupt services by repeatedly restarting the RHCertD daemon on a targeted host.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-10865 | CVE | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1593631 | CVE | Issue TrackingVendor Advisory |
| https://access.redhat.com/security/cve/CVE-2018-10865 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1593631 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat certification | 7.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 10, 2023 | Modified Analysis | [email protected] |
| Aug 5, 2022 | CVE Modified | [email protected] |
| Jun 4, 2021 | Initial Analysis | [email protected] |