CVE-2018-10905Improper Access Control in Redhat Cloudforms

Severity
7.8HIGHNVD
EPSS
0.3%
top 47.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateMay 13

Description

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-jjjj-c3mp-q822: CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms2022-05-13
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities2019-10-01
CVEList
CVE-2018-10905: CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms2018-07-24

📋Vendor Advisories

1
Red Hat
cfme: Improper access control in dRuby allows local users to execute arbitrary commands as root2018-07-20

💬Community

1
Bugzilla
CVE-2018-10905 cfme: Improper access control in dRuby allows local users to execute arbitrary commands as root2018-07-18
CVE-2018-10905 — Improper Access Control in Redhat | cvebase