CVE-2018-10869: Red Hat Certification

High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.

Affected products

  • Red Hat Certification: affected versions not specified
  • Red Hat Enterprise Linux: version 7.0 only

Published 2018-07-19. Last modified 2026-06-17.