CVE-2018-10870: Red Hat Certification
Critical severity, CVSS 9.8. EPSS: 6.1% chance of exploitation in the next 30 days.
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.
Affected products
- Red Hat Certification: affected versions not specified
Published 2018-07-19. Last modified 2026-06-17.