CVE-2018-10905
Last modified
CVE-2018-10905 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.
Metrics
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Cloudforms | 4.5 |
| Redhat | Cloudforms | 4.6 |
| Redhat | Cloudforms Management Engine | 5.8 |
| Redhat | Cloudforms Management Engine | 5.9 |
References
- https://access.redhat.com/errata/RHSA-2018:2561Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2745Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10905Issue Tracking, Mitigation, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2561Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2745Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10905Issue Tracking, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10905?
How severe is CVE-2018-10905?
How do I fix CVE-2018-10905?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1090In Pulp before version 2.16.2, secrets are passed into overr…5.5
- CVE-2018-10900Network Manager VPNC plugin (aka networkmanager-vpnc) before…7.8
- CVE-2018-10901A flaw was found in Linux kernel's KVM virtualization subsys…7.8
- CVE-2018-10902It was found that the raw midi kernel driver does not protec…7.8
- CVE-2018-10903A flaw was found in python-cryptography versions between >=1…7.5
- CVE-2018-10904It was found that glusterfs server does not properly sanitiz…8.8
- CVE-2018-10906In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermou…5.3
- CVE-2018-10907It was found that glusterfs server is vulnerable to multiple…8.8
- CVE-2018-10908It was found that vdsm before version 4.20.37 invokes qemu-i…6.5
- CVE-2018-10909Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-1091In the flush_tmregs_to_thread function in arch/powerpc/kerne…
- CVE-2018-10910A bug in Bluez may allow for the Bluetooth Discoverable stat…4.5
Are you affected by CVE-2018-10905?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
