CVE-2018-10863: Red Hat Certification
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
Affected products
- Red Hat Certification: version 7.0 only
Published 2021-05-26. Last modified 2026-06-17.