CVE-2018-10905: OS Command Injection
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.
Other sources
CloudForms Management Engine has a vulnerability that allows local users to execute arbitrary commands as root. An attacker with SSH access to the system can use the dRuby (DRb) module installed on the system to execute arbitrary shell commands using instanceeval().
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-10905.
What is affected by vulnerability CVE-2018-10905?
CloudForms Management Engine (cfme) versions 5.8.5.0 and 5.9.4.2, as well as Redhat Cloudforms versions 4.5 and 4.6, and Redhat Cloudforms Management Engine versions 5.8 and 5.9 are affected.
What is the severity of CVE-2018-10905?
The severity of CVE-2018-10905 is high (CVSS score of 7).
How can an attacker exploit CVE-2018-10905?
By having access to an unprivileged local shell, an attacker could exploit this vulnerability to execute commands as a high privileged user.
Are there any remediation steps available for CVE-2018-10905?
Yes, the recommended remedy is to update CloudForms Management Engine to version 5.8.5.0 or 5.9.4.2, or update Redhat Cloudforms to version 4.5 or 4.6, or update Redhat Cloudforms Management Engine to version 5.8 or 5.9.