Home / mailings
[RHSA-2018:2373-01] Critical: redhat-certification security update
Posted on 09 August 2018
-----BEGIN PGP SIGNED MESSAGE-----
Red Hat Security Advisory
Synopsis: Critical: redhat-certification security update
Advisory ID: RHSA-2018:2373-01
Product: Red Hat Certification
Advisory URL: https://access.redhat.com/errata/RHSA-2018:2373
Issue date: 2018-08-09
CVE Names: CVE-2018-10864 CVE-2018-10869 CVE-2018-10870
An update for redhat-certification is now available for Red Hat
Certification for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Certification for Red Hat Enterprise Linux 7 - noarch
The redhat-certification package provides partners with a unified web-based
user interface to certify their products for use on Red Hat Infrastructure.
It can currently be used in the latest releases of Red Hat Certified Cloud
and Service Provider Certification, Red Hat OpenStack Certification and Red
Hat Hardware Certification Programs.
* redhat-certification: rhcertStore.py:__saveResultsFile allows to write
any file (CVE-2018-10870)
* redhat-certification: /download allows to download any file
* redhat-certification: resource consumption in DocumentBase:loadFiltered
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.
These issues were discovered by Riccardo Schirone (Red Hat Product
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
5. Bugs fixed (https://bugzilla.redhat.com/):
1593627 - CVE-2018-10864 redhat-certification: resource consumption in DocumentBase:loadFiltered
1593780 - CVE-2018-10869 redhat-certification: /download allows to download any file
1593803 - CVE-2018-10870 redhat-certification: rhcertStore.py:__saveResultsFile allows to write any file
6. Package List:
Red Hat Certification for Red Hat Enterprise Linux 7:
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
The Red Hat security contact is <firstname.lastname@example.org>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2018 Red Hat, Inc.