CVE-2018-10905 — Improper Access Control in Redhat Cloudforms
Severity
7.8HIGHNVD
EPSS
0.3%
top 47.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 24
Latest updateMay 13
Description
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-jjjj-c3mp-q822: CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms↗2022-05-13
CVEList▶
CVE-2018-10905: CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms↗2018-07-24
📋Vendor Advisories
1Red Hat▶
cfme: Improper access control in dRuby allows local users to execute arbitrary commands as root↗2018-07-20
💬Community
1Bugzilla▶
CVE-2018-10905 cfme: Improper access control in dRuby allows local users to execute arbitrary commands as root↗2018-07-18